Unsecured Mars Hydro database exposed 2.7 billion IoT records
- Organization
- Mars Hydro
- Exploit
- Misconfiguration
- Industry
- Manufacturing
Security researcher Jeremiah Fowler reported in February 2025 that he had found an unprotected database holding 2,734,819,501 records, about 1.17 terabytes, linked to Mars Hydro, a China based maker of LED grow lights and other connected horticultural equipment. The database carried no password and no encryption.
The records sat in 13 folders, several of them holding more than 100 million entries each. They included Wi-Fi network names and passwords, IP addresses, device identifiers, API details and access tokens, along with error logs that revealed the operating systems, device models and app versions of the smartphones used to control the equipment. Fowler said the data appeared to relate to users of the Mars Pro app, published for iOS and Android, and that references to LG-LED Solutions Limited, a company registered in California, and to the Spider Farmer brand also appeared in the set.
Fowler sent responsible disclosure notices to the companies involved and public access to the database was cut off within hours, though he received no substantive reply. It was not established how long the database had been reachable or whether anyone other than the researcher had retrieved data from it.
The findings were shared with vpnMentor and published on February 12, 2025, with Infosecurity Magazine running the report at the same time. Fowler noted that exposed network names and passwords could support attacks against the home and business networks the devices were connected to.