It’s a rookie error, but all too common. MoviePass compounded their error by not responding fast enough when this was reported…:
[…] Mossab Hussein, a security researcher with security company SpiderSilk, found the exposed server on one of MoviePass’ subdomains, TechCrunch reports. The database held 161 million records and counting; 58,000 of those records contained payment card data. Hussein initially emailed MoviePass CEO Mitch Lowe, but when the executive didn’t respond to his message, the researcher contacted TechCrunch. MoviePass took the server down after the publication reached out.
After working with Hussein to review sample datasets, TechCrunch reports exposed records contain sufficient information to commit credit card fraud. In a sample of 1,000 records, more than half had a MoviePass member card number, balance, and expiration. The server also contained records of failed login attempts. None of the data on the server was encrypted.