Oracle's Ad Division Exposed Billions Of Records Through An Unsecured Server

Oracle's grip on the web may not be as big as Google. But still, its ad division is responsible for tracking about 1% of all web traffic.

That translates to billions of records.

And according to a report by Zach Whittaker in TechCrunch, the tech giant's data harvester has that many records of people from all over the world exposed to the open web due to leaving the server unsecured without a password.

The database in question was operated by BlueKai (later rebranded to 'Oracle Data Management Platform'), a cloud-based big data platform Oracle acquired in 2014 for over $400 million.

It's task is to help Oracle's cloud marketing, in order to enable marketers act on data across both known customers and new audiences and precisely target customers with a personalized message across all channels. That according to Steve Miranda, Oracle EVP, applications development.

To do what it's supposed to do, BlueKai tracks users around the web through cookies and other proprietary technology, and not limited to just Oracle users.

Instagram with QR code feature

BlueKai is said to be capable of tracking the websites people visit and which emails they open. Just like modern and other sophisticated trackers, BlueKai that collects a wide range of data from people, is also able to conclude, or guess, the interests of people, to understand their political views and even their income.

From its different sources, BlueKai also merges the data to create a unique fingerprint of a person's device, which itself can later be linked to other devices. All that is to make it capable of targeting users with the most optimal ads that appeal them.

Security researcher Anurag Sen found the database and reported his finding to Oracle through an intermediary, Roi Carthy, the chief executive at cybersecurity firm Hudson Rock and former TechCrunch reporter.

When reached for comment, Oracle spokesperson Deborah Hellinger said:

"Oracle is aware of the report made by Roi Carthy of Hudson Rock related to certain BlueKai records potentially exposed on the Internet.... While the initial information provided by the researcher did not contain enough information to identify an affected system, Oracle's investigation has subsequently determined that two companies did not properly configure their services. Oracle has taken additional measures to avoid a reoccurrence of this issue."
[block:block=87]

TechCrunch listed some examples of people who data was left open to the public web for the taking.

One, is a man in German who "used a prepaid debit card to place a €10 bet on an esports betting site on April 19. The record also contained the man's address, phone number and email address."

In an another example, it is said that "one of the largest investment holding companies in Turkey used BlueKai to track users on its website. The record detailed how one person, who lives in Istanbul, ordered $899 worth of furniture online from a homeware store. We know because the record contained all of these details, including the buyer’s name, email address and the direct web address for the buyer’s order, no login needed."

So BlueKai here, the cloud-based big data platform that is barely known outside marketing circles, has amassed one of the largest banks of web tracking data outside of the federal government.

With its database left unprotected on the internet, the sheer number of data easily made the incident one of the largest security lapses this 2020.

Under California state law, companies like Oracle are required to publicly disclose data security incidents. Under Europe's General Data Protection Regulation, companies can face fines of up to 4% of their global annual turnover for openly disregarding data protection and disclosure rules.

When the news first came out, Oracle declined to say if it informed those whose data was exposed about the security lapse. The company also declined to say if it had warned U.S. or international regulators of the incident.