Mcafee.com/activate uncovers a massive data trove exposed for anyone to see. A research team from VPN Mentor discovers that around 24GB database has been exposed, which was hosted on a Microsoft cloud server. The information contained addresses, income levels, and marital statuses of the users of 80 million US households.

The status is that of many organizations are not taking steps to secure their customer data and every so often one makes the news. Some of them may be exploited while being exposed; others will have been lucky.

Since millions of people based in the US have lost their private data via some database, this has made other natives concerned about securing their online information. Among thousands of entries, the researchers could not find anyone listed under the age of 40.

The exposed data include a mixture of coded information and non-coded information. Non-coded info includes street addresses, cities, states, counties, zip codes, latitude and longitude coordinates, ages, dates of birth, and first/last names along with middle initials. The data assigned coded a numerical value containing information, such as marital status, income, gender, dwelling type, and homeowner status.

In practice, what the coded and non-coded entries mean is that you could easily view someone’s name or address, but something like gender or title is instead assigned a numerical value. Some of the information is chained to coded values may not be possible to figure out: For example, “Income” or “Income” may be too obscure to put a salary range on it. However, if you see “Steve” and the gender assigned is then it’s probable that 1 = male on all their records.

In this way, even where data is assigned in a numerical code, you can piece together most of a person’s information. If the salary for people listed 70 and up is “10”, then 10 might be “retired”, “on a pension plan”, or something similar to that.

For what reasons the database is used?

In the upper end of the ages listed in this database, they could well be more susceptible to these kinds of tricks. The database was eventually taken offline by Microsoft, who has apparently notified the owners. Meanwhile, researchers have asked the public to try to help identify exactly whom this data belongs to.

They suspect that it has some sort of financial service connection, such as insurance or mortgaging or even perhaps healthcare. The specific age range is shown in the data looks at might have suggested a form of dating app for older generations, except it makes no sense for it to focus on households rather than individuals. The geo-vocational coordinates may associate this with some form of mobile app connection, as you’d typically expect to see that via portable apps as opposed something filled in on the desktop.

No matter what is the purpose of the database, the good news is that it’s currently offline. It also does not seem to be the case that it’s been used maliciously—for now, anyway. There isn’t a vast amount anyone can do in this situation beyond advising to be cautious of the usual social engineering frauds. In addition, keep the access of your Microsoft account strict.

