
A concerning data breach affecting the MyEstatePoint Property Search app, developed by India-based software developer NJ Technologies, has compromised the personal information of approximately 497,000 users.
The breach exposed sensitive details, including names, email addresses, plain-text passwords, mobile phone numbers, city information, business descriptors, and signup methods. The all-in-one real estate app boasts over half a million downloads on the Google Play store, predominantly serving the Indian market.
The discovery by the Cybernews research team unveiled a publicly accessible MongoDB server housing this extensive data, mirroring the app’s download count. The team identified and reported the exposed server on November 6th. Despite attempts to notify NJ Technologies, they received no response initially. However, the exposed instance has since been secured.
The compromised dataset poses significant risks, potentially enabling threat actors to exploit the information for unauthorized access, identity theft, and fraudulent activities. The team emphasized the severe implications, underlining the possibility of compromising affected individuals’ privacy and security.
According to the researchers, the leaked email addresses and plain-text passwords could be leveraged by scammers for various malicious activities, amplifying the risk of further security breaches and attacks. Attempts to obtain a comment from NJ Technologies regarding this security lapse have been unsuccessful thus far.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543