Moneycontrol PRO
Outskill Genai
HomeNewsTechnologyA server leak put student data from Byju's at risk, says report

A server leak put student data from Byju's at risk, says report

Before it was secured, the sever was left unprotected and vulnerable since June 14

June 30, 2021 / 22:08 IST
Before it was secured, the sever was left unprotected and vulnerable since June 14

An unsecured server at Salesken.ai had put student data from popular learning e-portal Byju's at risk. According to the report, the server had been unprotected since at least June 14, according to a report by Techcrunch.

Data found on the server contained student names and classes along with email addresses and phone numbers of parents and teachers. It also contained log chats between parents and staff and teacher's comments on their students. Copies of emails with codes to reset user accounts and internal Salesken.ai data were also found on the server.

The flaw was detected by security researcher Anurag Sen, who had asked the publication to help report it to the company. The server was then pulled offline.

Commenting on the incident, a WhiteHat Jr spokesperson said: “Salesken.ai, one of WhiteHat Jr’s vendors for India operations, has experienced a potential security incident. We are currently communicating with Salesken.ai about the incident and will take appropriate action in accordance with our rigorous security policies.”

Speaking with TechCrunch, Surga Thilakan, co-founder of Salesken.ai said, "Our assessment suggests the exposed device appears to be a non-production, staging instance of one of our integration services having access to less than 1% of India based end-of-life sales logs for a fortnight."

“Salesken.ai follows stringent data security norms and is certified under the highest standards of global security and safety. We have, in an abundance of caution, immediately severed access to the cloud device,” he added.

A follow-up mail from TechCrunch asking him why real user data was found on a staging server was not answered. The company has yet to reveal if any logs or data were downloaded because of the lapse.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Moneycontrol News
first published: Jun 30, 2021 08:18 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347