A massive data exposure at Mexican electronic document provider EDX Solutions has left an estimated 30 million sensitive records accessible online, with information connected to PepsiCo operations across Latin America accounting for much of the exposed material.
The incident involved an unsecured MongoDB database discovered in early July. Researchers found 48 databases containing approximately 292GB of information belonging to EDX and organizations using its document management services. The database was accessible without the protections needed to prevent outsiders from reaching its contents.
PepsiCo’s Colombian operations appear to have been the most heavily exposed. More than 221GB of the overall data was associated with Colombia, including a database containing over 11 million invoice transaction records. Researchers also found full invoice documents, identifiers, timestamps, configuration information, and at least one record containing plaintext credentials for an internal API.
The exposure extended well beyond Colombia. More than 42GB of information was associated with Peru, including records linked to PepsiCo Peru and building materials company Holcim. Data connected to organizations in the Dominican Republic, El Salvador, Costa Rica, and Ecuador was also identified.
The exposed information varied between databases but included invoices, tax-related documents, supplier information, employee account details, email addresses, and authentication data. Researchers also discovered API credentials, tokens, recovery codes, digital certificate information, and internal files.
Such records could provide useful material for highly convincing business scams. Detailed invoices and supplier relationships could help criminals impersonate trusted companies, redirect payments, or create fraudulent requests that closely resemble legitimate transactions. Exposed credentials and authentication information could potentially create additional risks if they remain valid.
The findings do not establish that PepsiCo’s own infrastructure was directly compromised. Instead, the data was exposed through EDX Solutions, demonstrating how information entrusted to an external service provider can create security risks for multiple client organizations at once.
Researchers discovered the database on July 2 and contacted EDX Solutions five days later. They received an initial response from the company, but communication reportedly stopped afterward. Mexico’s national computer emergency response team was contacted about the exposure in August.
It is not currently clear how long the MongoDB instance remained publicly accessible or whether unauthorized parties downloaded the information before researchers discovered it. EDX Solutions and PepsiCo had not provided a public explanation of the incident when the findings were published, leaving the full impact of the exposure unresolved.
