/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A researcher finds messaging app JusTalk, which has ~20M users, exposed a database with millions of conversations and call logs in plaintext since January 2022

Zack Whittaker / TechCrunch :

TechCrunch Zack Whittaker

Context & Ripple Effects

JusTalk is the latest entry in a long line of consumer apps caught leaving user communications wide open: Voipo left millions of call logs and texts exposed for months, Voxox streamed SMS traffic including password reset and 2FA codes in near real time, and Whisper leaked hundreds of millions of intimate messages tied to location data. What distinguishes this one is duration and content — a messaging app's own conversation archive sitting in plaintext since January 2022, found by TechCrunch's Zack Whittaker.

The pattern across these incidents is consistent: small-to-mid-size communication apps treat message history as an operational asset they must keep online, and misconfigure cloud storage rather than encrypt it at rest. With roughly 20M users, JusTalk sits squarely in the size band where these exposures keep recurring.

First-order effects

  • Millions of JusTalk users have had private conversations and call logs readable by anyone who found the database for over six months, with no way to know who accessed it before the researcher did.
  • JusTalk faces immediate remediation costs — securing the database, notifying affected users, and answering questions about why chat content was stored unencrypted at all.

Second-order effects

  • Competing messaging apps gain a marketing opening around end-to-end encryption and minimal data retention, pressuring the whole mid-tier video-calling market to justify what it stores server-side.
  • App store reviewers and enterprise buyers evaluating communication tools get a fresh case study for demanding encryption-at-rest attestations, raising the compliance bar for smaller developers.

Third-order effects

  • If the unsecured-database pattern keeps repeating — from AI.type's contact dump through Voipo, Voxox, and now JusTalk — regulators and platform gatekeepers are pushed toward requiring verifiable data-handling standards for consumer communication apps rather than trusting self-reported privacy policies.
  • The recurring exposure of retained conversation archives strengthens the argument that messaging products should architect for ephemerality and client-side encryption by default, making 'we kept everything on one open server' a design failure rather than an ops slip.

The trend: Consumer communication apps keep leaking entire message archives through misconfigured storage, steadily eroding trust in any messenger that retains plaintext conversations server-side.

Discussion

  • @zackwhittaker Zack Whittaker on x
    JusTalk has 20 million users around the world. The database had so much data in it that it was possible to follow users' entire conversations, including from children who were using the JusTalk Kids app to chat with their parents. https://techcrunch.com/...
  • @moonalice Roger McNamee on x
    There is no liability in the US for reckless exposure of consumer data and other security failures. As a result, corporate holders of even the most sensitive data are staggeringly careless. https://twitter.com/...
  • @zackwhittaker Zack Whittaker on x
    New: JusTalk left a huge database packed with millions of users' conversations and users' granular locations on a server since at least January 2022. All of the data was in plaintext, despite JusTalk's claims that it uses end-to-end encryption. https://techcrunch.com/...
  • @techcrunch @techcrunch on x
    Popular video calling and messaging app JusTalk claims to be both secure and encrypted. But a security lapse has proven the app to be neither after a huge cache of users' unencrypted private messages was found online, @zackwhittaker reports. https://techcrunch.com/...
  • @saramorrison Sara Morrison on x
    “One conversation chain contained enough personal information to identify a pastor who was using the app to solicit a sex worker who lists their phone number publicly for their services, including the time, location and the price of their meeting.” https://twitter.com/...