• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

NCIX Database Servers Containing Unencrypted User Data Cause Yet Another Data Breach

VSG

Editor, Reviews & News
Staff member
Joined
Jul 1, 2014
Messages
3,473 (0.97/day)
As if the Newegg data breach reported yesterday was not enough, NCIX decided to haunt everyone from the grave when news of a much larger data breach came out today. Readers of our website may have been aware that NCIX declared bankruptcy last December, and all their assets were put up for sale as part of a multi-day auction by the Able Auctions firm earlier this year. Most of the items on sale were innocuous, including remaining PC DIY components and office supplies, but an investigation coming out of Privacy Fly, a cyber security firm from Canada, is showing that something much more sinister ended up in the hands of people who also knew what they were doing. In particular, an unidentified male who called himself "Jeff", acting either independently or on behalf of another company, had procured the entire NCIX server farm at the auction and then sorted through the data to determine what was "useful" and what was not.

By this, he was referring to unencrypted and/or easily-cracked user data stored on the servers that NCIX had not bothered to remove or put behind a stronger password as the contents were laid bare for Privacy Fly to examine after the server was unlocked. These servers were put up for sale for $1500 (CAD) on Craigslist of all places, in a bold move effectively selling user data by the tens of thousands. "Jeff" confirmed he was in possession of hundreds of desktops, hard drives and more servers which, along with the StarWind iSCSI Software that was included in the auction and used by NCIX for all their years of existence meant every single customer and former employee was exposed by the breach. To be more specific, we are talking about financial records including payroll information, residence and email addresses, payment information and even Canadian SIN numbers all available to be seen and purchased by the lot. Be it the fault of NCIX or Able Auction, knowing that unencrypted data servers were sold without being wiped is terrifying, and we recommend taking appropriate actions as deemed for your country of residence.



View at TechPowerUp Main Site
 

Durvelle27

Moderator
Staff member
Joined
Jul 10, 2012
Messages
6,703 (1.56/day)
Location
Memphis, TN
System Name Black Prometheus
Processor |AMD Ryzen 7 1700X
Motherboard ASRock B550M Pro4|MSI X370 Gaming PLUS
Cooling Thermalright PA120 SE | AMD Stock Cooler
Memory G.Skill 64GB(2x32GB) 3200MHz | 32GB(4x8GB) DDR4
Video Card(s) |AMD R9 290
Storage Sandisk X300 512GB + WD Black 6TB+WD Black 6TB
Display(s) LG Nanocell85 49" 4K 120Hz + ACER AOPEN 34" 3440x1440 144Hz
Case DeepCool Matrexx 55 V3 w/ 6x120mm Intake + 3x120mm Exhaust
Audio Device(s) LG Dolby Atmos 5.1
Power Supply Corsair RMX850 Fully Modular| EVGA 750W G2
Mouse Logitech Trackman
Keyboard Logitech K350
Software Windows 10 EDU x64
I’ve never seen so many security breaches in my life in just a years time
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
I’ve never seen so many security breaches in my life in just a years time

Thing is, this isn't a breach. This is stupidity. They literally sold the unencrypted servers on the open market without wiping them.
 
Joined
Jul 16, 2014
Messages
8,118 (2.27/day)
Location
SE Michigan
System Name Dumbass
Processor AMD Ryzen 7800X3D
Motherboard ASUS TUF gaming B650
Cooling Artic Liquid Freezer 2 - 420mm
Memory G.Skill Sniper 32gb DDR5 6000
Video Card(s) GreenTeam 4070 ti super 16gb
Storage Samsung EVO 500gb & 1Tb, 2tb HDD, 500gb WD Black
Display(s) 1x Nixeus NX_EDG27, 2x Dell S2440L (16:9)
Case Phanteks Enthoo Primo w/8 140mm SP Fans
Audio Device(s) onboard (realtek?) - SPKRS:Logitech Z623 200w 2.1
Power Supply Corsair HX1000i
Mouse Steeseries Esports Wireless
Keyboard Corsair K100
Software windows 10 H
Benchmark Scores https://i.imgur.com/aoz3vWY.jpg?2
Thats were Linus (LTT) started out, bet he is laughing right about now.
 
Joined
Feb 3, 2012
Messages
200 (0.04/day)
Location
Tottenham ON
System Name Current
Processor i7 12700k
Motherboard Asus Prime Z690-A
Cooling Noctua NHD15s
Memory 32GB G.Skill
Video Card(s) GTX 1070Ti
Storage WD SN-850 2TB
Display(s) LG Ultragear 27GL850-B
Case Fractal Meshify 2 Compact
Audio Device(s) Onboard
Power Supply Seasonic 1000W Titanium
Thats were Linus (LTT) started out, bet he is laughing right about now.

I dunno, as an ex employee they probably have his social insurance number on there somewhere.
 
Joined
Nov 18, 2011
Messages
124 (0.03/day)
Location
Toronto, Canada
Processor Intel Atom 270
Cooling Passive
Memory 2GB DDR3-1333
Storage 160GB WD 2.5"
Case Custom
Power Supply Seasonic-Passive
Frankly... This is criminal negligence.
 

hat

Enthusiast
Joined
Nov 20, 2006
Messages
21,731 (3.41/day)
Location
Ohio
System Name Starlifter :: Dragonfly
Processor i7 2600k 4.4GHz :: i5 10400
Motherboard ASUS P8P67 Pro :: ASUS Prime H570-Plus
Cooling Cryorig M9 :: Stock
Memory 4x4GB DDR3 2133 :: 2x8GB DDR4 2400
Video Card(s) PNY GTX1070 :: Integrated UHD 630
Storage Crucial MX500 1TB, 2x1TB Seagate RAID 0 :: Mushkin Enhanced 60GB SSD, 3x4TB Seagate HDD RAID5
Display(s) Onn 165hz 1080p :: Acer 1080p
Case Antec SOHO 1030B :: Old White Full Tower
Audio Device(s) Creative X-Fi Titanium Fatal1ty Pro - Bose Companion 2 Series III :: None
Power Supply FSP Hydro GE 550w :: EVGA Supernova 550
Software Windows 10 Pro - Plex Server on Dragonfly
Benchmark Scores >9000
Dude... wat. I can't help but wonder if this was intentional somehow, nobody just gives away data like that.
 
Joined
Oct 22, 2014
Messages
13,210 (3.80/day)
Location
Sunshine Coast
System Name Black Box
Processor Intel Xeon E3-1260L v5
Motherboard MSI E3 KRAIT Gaming v5
Cooling Tt tower + 120mm Tt fan
Memory G.Skill 16GB 3600 C18
Video Card(s) Asus GTX 970 Mini
Storage Kingston A2000 512Gb NVME
Display(s) AOC 24" Freesync 1m.s. 75Hz
Case Corsair 450D High Air Flow.
Audio Device(s) No need.
Power Supply FSP Aurum 650W
Mouse Yes
Keyboard Of course
Software W10 Pro 64 bit
Dude... wat. I can't help but wonder if this was intentional somehow, nobody just gives away data like that.
The Administrators in charge of asset sales only care about cents in the dollar returns, not security.
Legally they should be liable if anything criminal results from this.
 

newtekie1

Semi-Retired Folder
Joined
Nov 22, 2005
Messages
28,472 (4.23/day)
Location
Indiana, USA
Processor Intel Core i7 10850K@5.2GHz
Motherboard AsRock Z470 Taichi
Cooling Corsair H115i Pro w/ Noctua NF-A14 Fans
Memory 32GB DDR4-3600
Video Card(s) RTX 2070 Super
Storage 500GB SX8200 Pro + 8TB with 1TB SSD Cache
Display(s) Acer Nitro VG280K 4K 28"
Case Fractal Design Define S
Audio Device(s) Onboard is good enough for me
Power Supply eVGA SuperNOVA 1000w G3
Software Windows 10 Pro x64
The Administrators in charge of asset sales only care about cents in the dollar returns, not security.
Legally they should be liable if anything criminal results from this.

After reading another article on what happened, it seems that NCIX was renting a warehouse to store all this stuff. But they didn't pay their rent, so the landlord sold it all without bothering to wipe it.

I don't think the landlord was legally obligated to wipe data. Maybe morally though.

What bothers me was all this data was stored unencrypted! That's just dumb.
 
Joined
May 13, 2010
Messages
5,702 (1.12/day)
System Name RemixedBeast-NX
Processor Intel Xeon E5-2690 @ 2.9Ghz (8C/16T)
Motherboard Dell Inc. 08HPGT (CPU 1)
Cooling Dell Standard
Memory 24GB ECC
Video Card(s) Gigabyte Nvidia RTX2060 6GB
Storage 2TB Samsung 860 EVO SSD//2TB WD Black HDD
Display(s) Samsung SyncMaster P2350 23in @ 1920x1080 + Dell E2013H 20 in @1600x900
Case Dell Precision T3600 Chassis
Audio Device(s) Beyerdynamic DT770 Pro 80 // Fiio E7 Amp/DAC
Power Supply 630w Dell T3600 PSU
Mouse Logitech G700s/G502
Keyboard Logitech K740
Software Linux Mint 20
Benchmark Scores Network: APs: Cisco Meraki MR32, Ubiquiti Unifi AP-AC-LR and Lite Router/Sw:Meraki MX64 MS220-8P

Indra18

New Member
Joined
Jan 26, 2018
Messages
17 (0.01/day)
I think this is shame for whole country like canada and byznis firms there.... just magine how many VPN services and seed boxes are running in canada now and all your data is in danger becouse ,,look on this case and try imagine..
if this happen in usa propaganda will use -russia hackers russia russia )))
Booth countries (usa and canada) is now third world!
just watch charlieboo313 youtube channel..
 
Joined
Sep 21, 2018
Messages
96 (0.05/day)
Location
Germany
Processor Ryzen 7 3700x
Motherboard AsRock X570M Pro4
Cooling Be Quiet Dark Rock Pro 3
Memory 4 x 16 GB Crucial Ballistix Sport LT red 3000C15 @ 3800C16 Micron rev E
Video Card(s) Zotac RTX 2070 mini
Storage Corsair MP510 1.92TB
Display(s) Samsung U32J592UQU 31.5" UHD + Fujitsu P19-2 19" 1280x1024
Case Jonsbo U3 mATX
Audio Device(s) ATH-M50
Power Supply Corsair SF600 600W SFX [currently RMAed]
Mouse Logitech G500
Keyboard QPAD MK-50 mechanical
Software Win10Edu_64
After reading another article on what happened, it seems that NCIX was renting a warehouse to store all this stuff. But they didn't pay their rent, so the landlord sold it all without bothering to wipe it.

I don't think the landlord was legally obligated to wipe data. Maybe morally though.

What bothers me was all this data was stored unencrypted! That's just dumb.
A quote from the linked article: "[Jeff] was helping NCIX’s landlord recover the money he was owed in exchange for being able to copy the source code, and database to aid his development team on a projec." That certainly doesn't sound legal and the owner of the warehouse had knowledge of it and seemed okay with it. And in Germany, you have to go through an arduous process when you want to remove a tenant owing you rent and being allowed to sell off their stuff to cover your cost has even higher legal restrictions. Selling something with personal data on it is pretty much illegal in any case and can incur fines of several tens to hundreds of thousands of Euros. I doubt it is much different in Canada. Even companies that went bankrupt have certain obligations still, like keeping records save and available for anywhere between 5 to 10 years and the people handling the bankruptcy can be held legally accountable.
 
Joined
May 13, 2010
Messages
5,702 (1.12/day)
System Name RemixedBeast-NX
Processor Intel Xeon E5-2690 @ 2.9Ghz (8C/16T)
Motherboard Dell Inc. 08HPGT (CPU 1)
Cooling Dell Standard
Memory 24GB ECC
Video Card(s) Gigabyte Nvidia RTX2060 6GB
Storage 2TB Samsung 860 EVO SSD//2TB WD Black HDD
Display(s) Samsung SyncMaster P2350 23in @ 1920x1080 + Dell E2013H 20 in @1600x900
Case Dell Precision T3600 Chassis
Audio Device(s) Beyerdynamic DT770 Pro 80 // Fiio E7 Amp/DAC
Power Supply 630w Dell T3600 PSU
Mouse Logitech G700s/G502
Keyboard Logitech K740
Software Linux Mint 20
Benchmark Scores Network: APs: Cisco Meraki MR32, Ubiquiti Unifi AP-AC-LR and Lite Router/Sw:Meraki MX64 MS220-8P
This also will screw over NCIX bc nobody will do biz with them. If you can't bother with rent how are you going to do other things?
 
Joined
Jul 16, 2014
Messages
8,118 (2.27/day)
Location
SE Michigan
System Name Dumbass
Processor AMD Ryzen 7800X3D
Motherboard ASUS TUF gaming B650
Cooling Artic Liquid Freezer 2 - 420mm
Memory G.Skill Sniper 32gb DDR5 6000
Video Card(s) GreenTeam 4070 ti super 16gb
Storage Samsung EVO 500gb & 1Tb, 2tb HDD, 500gb WD Black
Display(s) 1x Nixeus NX_EDG27, 2x Dell S2440L (16:9)
Case Phanteks Enthoo Primo w/8 140mm SP Fans
Audio Device(s) onboard (realtek?) - SPKRS:Logitech Z623 200w 2.1
Power Supply Corsair HX1000i
Mouse Steeseries Esports Wireless
Keyboard Corsair K100
Software windows 10 H
Benchmark Scores https://i.imgur.com/aoz3vWY.jpg?2
This also will screw over NCIX bc nobody will do biz with them. If you can't bother with rent how are you going to do other things?
NCIX went out of business 2016 i think.
 
Joined
May 13, 2010
Messages
5,702 (1.12/day)
System Name RemixedBeast-NX
Processor Intel Xeon E5-2690 @ 2.9Ghz (8C/16T)
Motherboard Dell Inc. 08HPGT (CPU 1)
Cooling Dell Standard
Memory 24GB ECC
Video Card(s) Gigabyte Nvidia RTX2060 6GB
Storage 2TB Samsung 860 EVO SSD//2TB WD Black HDD
Display(s) Samsung SyncMaster P2350 23in @ 1920x1080 + Dell E2013H 20 in @1600x900
Case Dell Precision T3600 Chassis
Audio Device(s) Beyerdynamic DT770 Pro 80 // Fiio E7 Amp/DAC
Power Supply 630w Dell T3600 PSU
Mouse Logitech G700s/G502
Keyboard Logitech K740
Software Linux Mint 20
Benchmark Scores Network: APs: Cisco Meraki MR32, Ubiquiti Unifi AP-AC-LR and Lite Router/Sw:Meraki MX64 MS220-8P
O. Haven't really kept up with that. Lol
 
Joined
Nov 11, 2010
Messages
27 (0.01/day)
Location
Saint Louis, Missouri USA
That is an incredible story.

Their e-commerce platform software they developed would probably have a development cost well in the tens of thousands of dollars, maybe as high as a hundred grand. Think, they would've had barcode integration and tying in with accounting. That would've had some value to the right buyer. With their web servers and source code, any talk of anything having been encrypted goes out the window.

I guess industries mature and they consolidate with fewer players, and NewEgg and Amazon have upped the burden of competing in e-commerce.
 
Joined
Jul 16, 2014
Messages
8,118 (2.27/day)
Location
SE Michigan
System Name Dumbass
Processor AMD Ryzen 7800X3D
Motherboard ASUS TUF gaming B650
Cooling Artic Liquid Freezer 2 - 420mm
Memory G.Skill Sniper 32gb DDR5 6000
Video Card(s) GreenTeam 4070 ti super 16gb
Storage Samsung EVO 500gb & 1Tb, 2tb HDD, 500gb WD Black
Display(s) 1x Nixeus NX_EDG27, 2x Dell S2440L (16:9)
Case Phanteks Enthoo Primo w/8 140mm SP Fans
Audio Device(s) onboard (realtek?) - SPKRS:Logitech Z623 200w 2.1
Power Supply Corsair HX1000i
Mouse Steeseries Esports Wireless
Keyboard Corsair K100
Software windows 10 H
Benchmark Scores https://i.imgur.com/aoz3vWY.jpg?2
This explains events a bit.

 
Joined
Aug 9, 2012
Messages
8 (0.00/day)
Location
Canada
Processor Intel i5 4690K
Motherboard AsRock Z97 Extreme6
Cooling custom water cooling
Memory 16GB Kingston HyperX DDR3
Video Card(s) EVGA GTX 1070
Storage Crucial MX100 512 GB (gaming) SSD, Crucial MX100 256 GB O/S SSD
Display(s) MSI Optix AG32C
Case Corsair Air 540
Audio Device(s) ASUS Strix Raid Pro
Power Supply Corsair HX850
Mouse Corsair M65
Keyboard Corsair K70 LUX
Software Windows 10 Pro 64 bit
Here's the article they (LTT) were referring to on their WAN show last Friday NCIX Data Breach
 
Joined
Sep 7, 2017
Messages
3,244 (1.34/day)
System Name Grunt
Processor Ryzen 5800x
Motherboard Gigabyte x570 Gaming X
Cooling Noctua NH-U12A
Memory Corsair LPX 3600 4x8GB
Video Card(s) Gigabyte 6800 XT (reference)
Storage Samsung 980 Pro 2TB
Display(s) Samsung CFG70, Samsung NU8000 TV
Case Corsair C70
Power Supply Corsair HX750
Software Win 10 Pro
I’ve never seen so many security breaches in my life in just a years time

I'm not even sure this qualifies as the usual. It's just plain stupidity.
 
Top