Debt Collection: How an Unsecured ElasticSearch Instance Exposed Thousands of Borrowers

The UpGuard research team have discovered and secured an exposed ElasticSearch instance storing data from the debt collection system ENCollect. The server contained data relating to loans from various Indian and African financial services companies, amounting to 1,686,363 records and 5.8GB in storage size. Personal data revealed included names, loan amounts, date of birth, and account numbers. When alerted, the Indian Computer Emergency Response Team responded promptly, aiding in the securing of the data.