IoT Vendor Orvibo

NJCCIC Data Breach Notification

Original Release Date: 7/8/2019

Summary

Internet of things (IoT) vendor Orvibo leaked billions of user records via an exposed and unsecured ElasticSearch server. Orvibo runs the smart appliance platform SmartMate, used to manage a modern smart home. The exposed data includes logins, password resets, device heartbeats, logouts, customer email addresses, device IP addresses, usernames, and MD5-hashed passwords. A threat actor could use password reset codes to lock users out of their accounts. The security team at vpnMentor discovered the misconfigured server a few weeks ago and have attempted to contact Orvibo; however, the company has yet to respond or secure the server. More information can be found in the Forbes article.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.