WeMystic left 13.3 million user records exposed in an open database
- Organization
- WeMystic
- Exploit
- Misconfiguration
- Industry
- Consumer Web Services
WeMystic, a content platform offering astrology, numerology, tarot and spiritual guidance, left a MongoDB database reachable over the internet with no password, exposing 34 gigabytes of data about its users. The Cybernews research team found the instance and published its findings on November 30, 2023.
A collection within the database named "users" held 13.3 million records. According to the researchers, the exposed fields included names, email addresses, dates of birth, IP addresses, gender, horoscope signs and assorted user system data. Passwords and payment card details were not listed among the exposed fields.
The researchers said the database was accessible for at least five days before it was secured, and that WeMystic closed it following the disclosure. The company did not respond to a request for comment before the research was published.
Cybernews said the combination of contact details, birth dates and self declared spiritual interests would give attackers unusually specific material for phishing, spam and targeted manipulation. WeMystic serves mainly Brazilian, Spanish, French and English speaking audiences and also runs an online shop selling stones, tarot cards, chakras and similar products. No evidence was reported that anyone other than the researchers had accessed the exposed data, and no regulatory filing or company statement followed in the reporting period.