Mortgage Financial Technologies Company 8Twelve revealed 717,814 records on the Internet

Created with Sketch.

Mortgage Financial Technologies Company 8Twelve revealed 717,814 records on the Internet

Security researcher Jeremiah Fowler along with the Website Planet research team discovered an open, password-protected database that contained 717,814 records and personally identifiable information (PII) of thousands of Canadian citizens. This data contained information related to mortgage loans, including names, phone numbers, email addresses, physical addresses, and more. Many of the listings we saw appeared to be “with a mortgage”. These are records of people who want to buy a house, refinance, obtain a capital credit line or purchase an investment property.

After further research there were multiple references to 8Twelve Financial Technologies Inc. the canadian We immediately sent a responsible disclosure notice and 8Twelve acted quickly and professionally by restricting public access within hours of our discovery.

We have seen multiple references to the INFIN8 platform within the publicly exposed database. It may have been an end-to-end customer relationship management (CRM) repository.

The database contained one folder named “Requester” and five folders named “Application”. The records included candidate names, emails, work, home and cell phone numbers. Some records contained physical addresses, state and county. Because most data can relate to a specific individual, data found in records can be considered personally identifiable information (PII).

In a random sample of 10,000 records, the term “email” returned 18,382 results. Each record displayed contained 2 email addresses; one belonging to the requester accompanied by one counterpart from 8Twelve of the agents who received the lead.

Almost all common email services appeared in the data: Gmail 13,695, Yahoo 3,406, along with Outlook, iCloud, AOL and smaller numbers from several other email providers. /

Leave a Reply

Your email address will not be published. Required fields are marked *

Skip to content