An open and publicly available MongoDB instance exposed 6,772,269 records on Iranian drivers. Each record was unique, so the estimated number of unique entries is about 1-2 million. No company affiliation was available throughout the records. No matter who owned it, the fact alone that such highly sensitive PII (personally identifiable information) was available in the wild for at least 3 days, is scary. The lack of authentication allowed the installation of malware or ransomware on the MongoDB servers.”]
Source: https://securitydiscovery.com/iranian-ride-hailing-app-database-exposure/

