Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Threat Actor Claims Nearly 20,000 User Profiles Exposed in Firebase Database

Threat Actor Claims Nearly 20,000 User Profiles Exposed in Firebase Database

By: Jordan Vector Cybersecurity Expert

Last updated: August 5, 2026

Human Written
Threat Actor Claims Nearly 20,000 User Profiles Exposed in Firebase Database
  • A threat actor claims a publicly accessible Firebase Firestore database exposed nearly 20,000 user profiles from an Indian social networking app.

  • The alleged records include password hashes, contact details, device information, and other account data, according to a post on X.

  • The affected organization has not issued a public statement, and no independent verification has confirmed the claims.

A threat actor claims to have found a publicly accessible Firebase Firestore database belonging to an Indian social networking application. According to a post shared on X, the database was allegedly left open without authentication, allowing anyone to access stored user information.

According to the post, the exposed database reportedly contained 19,983 user profiles. The threat actor also shared sample records to support the claim. The samples allegedly show the type of information stored inside the database.

At the time of writing, the social networking platform has not released an official statement about the alleged exposure. No independent cybersecurity researchers or media organizations have publicly confirmed that the database belongs to the application or verified the authenticity of the records.

According to the post, the alleged exposure resulted from a publicly readable Firebase Firestore database rather than a direct attack on the organization’s internal systems.

Alleged Database Contains Nearly 20,000 User Profiles

According to the post, the exposed database allegedly includes 19,983 SHA-1 password hashes, email addresses, phone numbers, dates of birth, device identifiers, Firebase Cloud Messaging (FCM) tokens, profile details, and other account metadata.

The shared samples reportedly show several user records containing these fields. According to the post, the database was accessible because the Firebase Firestore instance was improperly configured.

Firebase Firestore is a cloud database that many mobile and web apps use to store user information. Developers control who can view or edit the stored data by setting security rules. If those rules are configured incorrectly, databases can become publicly accessible over the internet.

According to the post, this appears to be what happened in this case. The claim points to a database that could allegedly be viewed without requiring authentication.

The post does not state how long the database remained exposed. It also does not indicate whether anyone besides the threat actor accessed or downloaded the information.

Password Hashes and Device Tokens Could Present Security Risks

According to the post, one of the exposed fields includes SHA-1 password hashes instead of plain text passwords.

Password hashes hide the original password by converting it into another value. However, SHA-1 is an older hashing method. Depending on how it was implemented and whether additional protections were used, attackers may attempt to crack some hashes after obtaining them.

The alleged dataset also includes Firebase Cloud Messaging tokens. These tokens help applications deliver notifications to users’ devices. According to the post, exposure of these tokens could require them to be replaced if the claims are confirmed.

The reported records also contain personal information such as phone numbers, email addresses, dates of birth, and device identifiers. Criminals often use this type of information to build detailed profiles for phishing or other scams.

The post does not claim that passwords were stored in plain text. It only states that SHA-1 password hashes were present in the alleged database.

Organization Yet to Respond

The organization linked to the alleged database has not publicly responded to the claims. At the time of writing, no independent investigation has confirmed whether the exposed records originated from the social networking application.

According to the post, the incident involved a publicly accessible Firebase Firestore database instead of a traditional network breach. If confirmed, it would add to the growing number of incidents linked to cloud database misconfigurations rather than direct compromises of company systems.

The post also states that the threat actor published sample records to support the claim. However, those samples alone do not independently confirm the authenticity of the database or its source. Until additional evidence becomes available, the full scope of the alleged exposure remains unknown.

In a separate development, Microsoft has warned of an active malware campaign that spreads through infected USB drives, replaces copied cryptocurrency wallet addresses with attacker-controlled ones, and routes stolen data through the Tor network.

Share this article

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.