#i have an urgent instance about my company's neo4j instance, a fraud user created 80+instances today
12 messages · Page 1 of 1 (latest)
Not sure how the fraud happens, but we believe there are huge security holes here. We have been using our developer account for NEO4J login. Tonight after we saw the huge bills alert, we went to NEO4J, found over 80 instancec created today. Those istances were created in two batches, with 2 IPs. We immediately took all evidences, filling police report, meanwhile we changed the password of this account and disconnect all devices, and disconnect the Google account connection to NEO4J. However, we found my team member can still do whatever actions on NEO4J dashboard, even though he can not login to Google, Gmail or any other Google services, This is a huge security risk.
we dont know what we can do to prevent the frauder to keep making more instances on NEO4J.
@zealous heron
@sage pumice I just saw this, please DM - your company name and the version of Neo4j you are working with.
Hi Ari, Pinged you all the project and company info.
Thank you! On it
if you see the activity log, there have been 2 bulk creation on Sat morning and evening using those two IPs
Thanks Reynold please send me this info on DM if possible and I would like to keep the IP info off the public strings if possible
I have notified the teams and ask for them to look into this stat!
deleted my previous message and moving the discussions to DM