company logo

Product

Our Product

We are Reshaping the way Developers find and fix vulnerabilities before they get exploited.

Solutions

By Industry

BFSI

Healthcare

Education

IT & Telecom

Government

By Role

CISO

Application Security Engineer

DevsecOps Engineer

IT Manager

Resources

Resource Library

Get actionable insight straight from our threat Intel lab to keep you informed about the ever-changing Threat landscape.

Subscribe to Our Weekly Threat Digest

Company

Contact Us

Have queries, feedback or prospects? Get in touch and we shall be with you shortly.

loading..
loading..
loading..
Loading...

Data Breach

loading..
loading..
loading..

1.5B Records Exposed! Disclosing Massive Real Estate Data Breach

Discover massive real estate data breach exposing 1.5 billion records, including celebrities and politicians. Is your information at risk?

27-Dec-2023
4 min read

Security researcher Jeremiah Fowler reportedly disclosed a massive real estate data breach targeting prominent personalities across the industries. The exposed database, linked to the New York-based Real Estate Wealth Network, laid bare a staggering 1.5 billion records, encompassing sensitive real estate ownership data of diverse individuals, including high-profile figures like celebrities and politicians.

Database Details

Real Estate Wealth Network's Vulnerable Vault

The non-password-protected database, totaling a mammoth 1.16 TB, housed 1,523,776,691 records. These were thoroughly categorized into folders, offering a panoramic view of individuals' real estate affairs. From property history to court judgments, the trove encompassed a plethora of information, including names, physical addresses, phone numbers, and more.

Responsible Disclosure and Swift Action

Fowler, upon validating the authenticity of the disclosure, promptly alerted vpnMentor, initiating immediate incident reporting. Also, thanks to them for helping us with their critical insights on the incident, but it appears that prompting Real Estate Wealth Network to secure the exposed database has not been too early. Despite this, the duration of the database's exposure and potential unauthorized access remained elusive, necessitating an internal forensic audit for clarity.

realestatewealthnetworkbreach4-1.png

realestatewealthnetworkbreach5-1.png

realestatewealthnetworkbreach2-1.png

realestatewealthnetworkbreach1.jpg

Legal Nuances: Semi-Public Records and Varying Accessibility

US Property Tax Records Landscape

In the United States, property tax records are considered semi-public, yet accessibility varies across 3,144 counties. Disparities in online availability create challenges, with some locales requiring in-person access visits. While transparency is a goal, the lack of centralized record-keeping accentuates the complexities of property tax data access.

Lead Generation Dynamics

Drawing on personal experience as a former real estate agent, Fowler’s disclosure also highlights the lucrative lead generation business. With an estimated $12.01 trillion in American mortgages, the exposed database becomes a goldmine for investors seeking potential deals. The comprehensive details on Fowler's own property, juxtaposed with celebrity data, underline the database's scope.

Real Estate Wealth Network

REWN's Foundations and Offerings

Founded by Cameron Dunlap in 1993, Real Estate Wealth Network emerged as an online education platform for real estate enthusiasts. Offering resources at a fee, including a $1,450 annual charge for data access, the platform caters to a diverse audience seeking mentorship and information for real estate ventures.

Data Feeds and Logging Records

The exposed database seemingly constituted REWN's extensive collection, potentially sold as divided data feeds. A glimpse into daily logging records from April to October 2023 revealed internal user search data, encompassing names, phone numbers, emails, and accessed files. This raised concerns about the extent of potential exposure and data misuse.

Potential Risks: From Celebrity Privacy to Financial Fraud

Celebrity Exposure: A Real Threat

The revelation of celebrities' home addresses poses tangible risks to their personal safety and privacy. With real-world incidents like the home invasion of Paul Pelosi, the need for safeguarding the privacy and security of famous individuals becomes paramount.

Misuse of Real Estate Tax Data

While real estate tax data serves transparency and assessment purposes, its misuse harbors risks. Criminals could exploit this information for social engineering or phishing attacks, targeting individuals based on financial status or vulnerability. The exposed records' granularity, such as cash purchases or mortgage status, amplifies the potential for targeted financial fraud.

Escalating Risk: Property and Mortgage Fraud

The growing menace of property and mortgage fraud underscores the vulnerabilities inherent in real estate transactions. Criminals, armed with stolen identities, forge ownership documents and manipulate property transfers, potentially leading to financial losses and legal quagmires.

Recommendations: Cautionary Measures and Data Security Advocacy

Fowler strongly advocates caution among property owners when sharing personal information, emphasizing the importance of understanding the risks associated with semi-public data. Acknowledging the absence of imminent risk for individuals in the REWN database, he stresses the illustrative nature of potential scenarios and reaffirms his commitment to ethical research practices.