Experts from security firm Kromtech discovered the Mexican VAT refund site MoneyBack exposed 400GB of sensitive information. The data leak was the result of a misconfigured Apache CouchDB database containing roughly 500,000 customers passport details, credit card numbers, travel tickets. The database appears to be connected with MoneyBack, a leading provider of tax refund services for international travelers in Mexico. The most dangerous aspect of this discovery is the massive amount of data totaling more than 400GB”]
Source: https://securityaffairs.co/wordpress/62893/data-breach/moneyback-data-leak.html