Researcher finds unsecured ElasticSearch server owned by a Chinese public security department that leaked databases with 90M+ records of people and businesses
Sergiu Gatlan / BleepingComputer :
Context & Ripple Effects
This is the third Elasticsearch exposure BleepingComputer has reported in as many months, and the pattern is consistent: a Panama citizen database with ~3.5M records in May, then FMC Consulting's cluster leaking 20M+ resumes in June, now a server owned by a Chinese public security department itself. The difference this time is the owner — the leak comes from inside the state security apparatus, not from HR firms or private companies.
First-order effects
- The Chinese public security department must secure or take offline the exposed server, and the personal and business records it held are now discoverable by anyone who found the open instance before the researcher's disclosure.
Second-order effects
- Elastic faces renewed pressure to make its default configuration safe for non-expert operators, since every one of these incidents traces to clusters left public rather than to a product vulnerability; meanwhile Chinese government data holders join private firms like FMC Consulting as repeat examples in researchers' disclosure reports.
Third-order effects
- If state-run databases keep appearing alongside corporate leaks — culminating later in exposures like the 800M-record Chinese database with facial images and ID numbers and the Shanghai police dashboard left open for over a year — the pattern points toward default-open database deployments being treated as a systemic governance failure rather than isolated misconfigurations, pushing regulators toward mandatory configuration audits for large record holders.
The trend: Unsecured Elasticsearch clusters have become a recurring class of mega-leak spanning private HR firms and Chinese government agencies alike, with each disclosure widening scrutiny of how default configurations expose national-scale citizen databases.