WinStar app customer data exposed by unsecured Dexiga database
- Organization
- WinStar World Casino and Resort
- Exploit
- Misconfiguration
- Industry
- Casinos and Gaming
TechCrunch reported on February 9, 2024 that a database holding customer records from the My WinStar mobile app had been sitting on the internet without a password. The app is used by guests of WinStar, the Oklahoma casino and resort that bills itself as the world's largest, and is built and maintained by Dexiga, a software startup based in Nevada.
Security researcher Anurag Sen located the exposed logging database, which could be read in an ordinary web browser by anyone who knew its public IP address. The records contained full names, home addresses, email addresses, phone numbers, gender and device IP addresses. None of it was encrypted, although dates of birth were partly masked. An internal Dexiga account and password belonging to the company's founder also appeared in the logs.
The database held rolling daily logs going back to January 26, and Dexiga attributed the exposure to a log migration carried out that month. The company took the data offline shortly after being contacted and said it was continuing to investigate the incident and monitor its systems.
Dexiga characterized the contents as publicly available information and said no sensitive data had been exposed. It did not say how many people were affected or whether it would notify WinStar or the app's users. WinStar's general manager did not respond to requests for comment.