Personal information of most of Ecuador's population, including 6.7M children, left exposed online with home addresses, phone numbers, work information, more
Elasticsearch server leaks personal data on Ecuador's citizens, their family trees, and children, but also some users' financial records and car registration information.
Context & Ripple Effects
Ecuador's exposure is the latest and largest entry in a string of unauthenticated Elasticsearch incidents: an unprotected cluster exposing ~3.5M Panama citizens' ID data surfaced months earlier in a nearly identical find, and Russia's 20M-record tax database leak followed weeks later on AWS-hosted Elasticsearch. The country also carries prior form in this genre — an unsecured database of 93.4M Mexican voter records was found on AWS back in 2016.
What distinguishes the Ecuador case is scope and sensitivity: most of the population including 6.7 million children, with family trees, financial records, and car registrations layered on top — from a government that already runs the ECU-911 surveillance network of 4,300 cameras and 16 monitoring centers, making its citizens unusually heavily databased.
First-order effects
- Millions of Ecuadorian adults and children now have home addresses, phone numbers, and work information exposed to anyone who found the open server, with some users' financial and vehicle-registration records adding fraud leverage.
Second-order effects
- The recurrence of the same misconfiguration across countries — Panama, Russia, Mexico — puts direct pressure on Elasticsearch and cloud providers' default settings, since each new find is effectively a public indictment of permissive out-of-the-box access controls.
Third-order effects
- When national-scale citizen databases keep leaking through one product's default configuration, the pattern pushes governments toward binding data-protection rules and secure-by-default requirements for any vendor hosting state personal data — the same accountability gap the Equifax Argentina plain-text portal exposed two years earlier.
The trend: Cloud databases holding entire nations' personal records are leaking through misconfiguration rather than hacking, making default-permission hygiene the decisive variable in state data security.