A publicly accessible server with email logs reveals how much information such infrastructure holds–including evidence of attackers looking for it.
Update 4/30/26: The article has been updated to clarify that the data leak originated from IceWarp India and pertained to its email communications with Indian customers and IceWarp HQ. Data from EU and US branches of IceWarp and their customers were not affected.
IntroductionThe UpGuard Research team can now disclose that a publicly accessible Elasticsearch server belonging to IceWarp India holding more than 52 million records was discovered on Tuesday, March 24th 2026. The server contained email and other application logs relevant to both internal and client operations at the India branch of the company, with over 172,000 unique email addresses across 1,680 unique domains, just in the 10% sample analyzed. These logs included both plain text and hashed passwords for IceWarp India personnel. Internal communications between the India branch and other branches of IceWarp were discovered along with emails from IceWarp India to their customers.
Among the IceWarp India customers included in the communications are finance conglomerates Shriram and Bajaj Housing. Specific data points include the “to” and “from” pairs of email addresses for those sending and receiving the emails, timestamps, (sometimes partial) subject lines and message previews. The messages present regarded automated monitoring of internal and client resources, with reports being mailed to various stakeholders for each project. Also present are transactional emails from IceWarp India to their customers, such as invoices and contracts. The IceWarp India employee credentials pose even more of a problem, especially if the exposed accounts have elevated permissions among the hosted email systems.
About IceWarp IndiaIceWarp Inc., founded in 1998 and operating out of the Czech Republic, produces IceWarp Mail Server, an enterprise messaging and collaboration suite competing with products such as Microsoft Exchange and the G-Suite. Headquartered in the Czech Republic, IceWarp has five major offices around the world, including one in Mumbai, India. The exposed logs belonged to IceWarp India.
In an email to UpGuard, IceWarp confirmed that the scope of the breach pertained to IceWarp India, not other global branches:
“The office branch that this incident concerns is IceWarp India. The incident was strictly limited to email communication within the Indian branch (between the Indian branch and Indian customers/partners, or between Indian branch and IceWarp HQ). Any reference to IceWarp Inc. (US entity) or IceWarp in general is misleading for EU and US customers – European or United States customer data and main global systems were not affected.”
Data analysisThere were two types of indices present on the Elasticsearch server, daily logs averaging a couple gigabytes, and a massive 52GB “processed” log that contained an aggregate of the daily logs with some additional information. For analysis, UpGuard obtained a 10% sample of the processed log file and one of the daily logs in its entirety.

Two types of IceWarp India credentials were discovered among the log files:

In addition to the credentials, the logs also contained authentication events such as successful and failed attempts as well as the remote IP address associated with the event. Dozens of internal IceWarp India users had hundreds of failed and successful login attempts, likely suggesting a brute force attack against them. W3C HTTP access logs present in the dataset also show exploitation scanning by external IP addresses against authentication endpoints. While neither of these types of attempts can be confirmed successful, the fact that threat actors were already looking at a system hosting publicly accessible credentials makes it very likely that these credentials are at risk.
Email DetailsThe logs originate from a Mumbai-based node in IceWarp India's cloud hosting cluster. The logs would normally be used internally by IceWarp India's operations team for server monitoring, debugging mail delivery issues, troubleshooting authentication problems, and SIEM/security event analysis.
Several of IceWarp India's customers have received emails logged in the exposed data set.
| Company | Email Count |
|---|---|
| Aavas Financiers | 79,897 |
| Bajaj Housing Finance | 41,356 |
| NCML | 8,028 |
| Indostar Capital | 7,579 |
| Adani Group | 4,058 |
| WNS Global Services | 2,602 |
| Metropolis Healthcare | 2,550 |
| Alembic Pharma | 1,588 |
| Shriram Finance | 1,484 |
| Teleperformance | 1,165 |
While some of these communications regard operation monitoring, email subject lines included in the logs also show references to contracts, invoice generation, POC agreements with named enterprises and pricing discussions. This indicates that business emails from IceWarp India to their clients are logged as part of this data set. Emails and replies from clients to Icewarp India are not present.

Email logs can reveal all types of sensitive information, from credentials, to operational details, to sensitive communication content. Hosted enterprise solutions, by their nature, outsource the risk of storing this information to a specialty provider. However, when a provider suffers a data leak, many organizations must now consider the consequences. The exposed email logs contain several layers of exposure that require attention.
Critically, the logs show that active exploitation attempts were already occurring during the capture window. One IP address was systematically probing dozens of known-vulnerable endpoints (Nacos, WordPress admin, ColdFusion, router CGI, backup scripts) using automated scanners. Another IP generated over 3,000 failed authentication attempts. These actors were already aware the server existed. The question raised by the exposure is whether any of them also accessed the Elasticsearch index and exfiltrated this data before it was discovered.
An email infrastructure compromise is inherently a supply chain attack vector. Control over mail routing or account access at an email hosting provider can be weaponized against any downstream system that uses email for authentication, notifications, or business communication.
Get in touch or book a free demo.
Learn more about the latest issues in cybersecurity.
UpGuard's monthly newsletter cuts through the noise and brings you what matters most: our breaking research, in-depth analysis of emerging threats, and actionable strategic insights.
Request a free cybersecurity report to discover key risks on your website, email, network, and brand.
Instant insights you can act on immediately
Hundreds of risk factors including email security, SSL, DNS health, open ports and common vulnerabilities