A significant security breach has exposed 2.7 billion records containing sensitive user data, including Wi-Fi network names, passwords, IP addresses, and device identifiers. The breach has been linked to Mars Hydro, a China-based grow light manufacturer, and LG-LED SOLUTIONS LIMITED, a California-registered firm.
Unsecured Database Exposes Sensitive Information
Cybersecurity researcher Jeremiah Fowler, in collaboration with vpnMentor, discovered an unprotected 1.17-terabyte database that was publicly accessible without password protection or encryption. The leaked records included:
- Wi-Fi SSIDs (network names) and passwords in plain text.
- IP addresses, device IDs, MAC addresses, and operating system details (iOS/Android).
- API tokens, app versions, and error logs labeled “Mars-pro-iot-error” or “SF-iot-error.”
The exposed database contained logs and monitoring records from IoT devices sold globally. Notably, Mars Hydro’s Mars Pro app, used for controlling IoT-enabled grow lights and climate systems, was implicated despite its privacy policy claiming no user data collection.
Link to LG-LED SOLUTIONS and Mars Hydro
Further investigation traced the records to LG-LED SOLUTIONS LIMITED, a company registered in California. The exposed data included API details and URL links to Mars Hydro, Spider Farmer, and LG-LED SOLUTIONS—businesses that manufacture and sell agricultural grow lights, fans, and cooling systems.
Many logs contained sensitive tokens, device types, and network credentials, raising concerns about potential unauthorized access.
Upon notification, Mars Hydro and LG-LED SOLUTIONS acted quickly, restricting database access within hours. However, it remains unclear whether LG-LED SOLUTIONS directly managed the database or if a third-party contractor was involved. The extent of unauthorized access remains unknown.
The exposed data poses severe security risks:
- Network Infiltration: Attackers could use leaked Wi-Fi credentials to access home or business networks, enabling data interception, ransomware attacks, or man-in-the-middle exploits.
- Botnet Recruitment: IoT devices could be hijacked for Distributed Denial-of-Service (DDoS) attacks, similar to previous breaches involving the Matrix hacker group.
- Physical Threats: Malicious actors could manipulate smart grow lights, fans, or climate systems, potentially damaging crops.
Cybersecurity experts warn of the “nearest neighbor attack,” a tactic previously used by Russian GRU hackers to breach networks via nearby Wi-Fi vulnerabilities.
To mitigate risks, experts urge IoT manufacturers and users to:
- Encrypt sensitive data and replace plain-text credentials with tokenized values.
- Segment networks to isolate IoT devices from critical systems.
- Conduct regular audits and penetration testing.
While Mars Hydro and LG-LED SOLUTIONS have yet to comment on the breach’s origins, Fowler emphasized that his findings aim to raise awareness about IoT security risks, with no evidence of direct misuse—yet.
This incident serves as a stark reminder of the urgent need for robust security measures in the IoT ecosystem.















Comments