Tokee Messaging App MongoDB Data Exposure | MSSP Advisory
High
DateMay 14, 2026
📋Executive Summary
Security researchers found an unsecured MongoDB database belonging to Deucetek, developer of the Tokee messaging app, exposing 1.2 million users' personal data including messages, contact information, and authentication tokens. The database was publicly accessible without authentication controls, allowing anyone to view and download the complete dataset. This represents a classic misconfiguration where cloud database security settings were not properly implemented.
⚠️Why It Matters for MSSPs
Your clients running MongoDB instances face the same exposure risk if database security configurations are not properly audited and hardened. As their MSSP, you need to verify that client MongoDB deployments have authentication enabled, network access controls configured, and are not accidentally exposed to the public internet. Missing this puts you in the position of explaining why a client's database was breached when basic security controls could have prevented it.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.