A security researcher Bob Diachenko discovered a secret terrorist watchlist with 1.9 million records that were exposed on the internet for three weeks between July 19 and August 9, 2021.
In July, Diachenko discovered an unsecured Elasticsearch cluster containing 1.9 records of sensitive information on individuals, such as names, country citizenship, gender, date of birth, passport details, and no-fly status.
At the time of this writing is not clear if the unsecured server was operated directly by the a U.S. government agency, a third-party, or in the worst case by a threat actor that obtained it.