Thousands of popular mobile apps have hard-coded backend credentials which could allow anyone to access millions of sensitive records. Attackers can gain access to huge amounts of sensitive data records like medical information, credit card data, photos, voice, audio- and video-records, money transaction records, etc. The largest number of records found through one single app was 2,611,760. On average, every app gave access to 70,000 records, the researchers found. They also found a mobile Trojan using a BaaS service to store stolen text messages.”]

