Warning - Active ICO Complaint Filed - 10 March 2026 - topeaglerservers.com
Security Disclosure - 10 March 2026

TopEaglerServers
left 27,611 users
fully exposed.

No hacking required. No special tools. A free account and two API endpoints. Every email address, every server record, and children's school emails - all publicly accessible. The platform was notified and chose silence.

ICO Complaint Filed 72-Hour Deadline Missed Breach Confirmed in Writing Children's Data Affected Follow on Discord
27,611
Users Exposed
20,564
Server Records
5,880+
School Domains
0
Users Notified by TES

What Happened

On 7 March 2026, security researcher Snelsterendier discovered that TopEaglerServers (topeaglerservers.com) - a browser-based Minecraft (Eaglercraft) hosting platform - had left its entire user and infrastructure database accessible on the open internet with no authentication and no access control of any kind.

The platform's backend API on port 3000 exposed the following administrative endpoints to any user with a free account:

EndpointData Returned
/admin/usersAll 27,611 user records - full email addresses, usernames, admin flags, credit balances, activity timestamps, account IDs
/admin/serversAll 20,564 server records - live ports, Docker container IDs, real-time memory/CPU/disk stats, payment history
/admin/configFull internal system configuration including filesystem paths and operational infrastructure details

Additionally, hidden directories (EaglerhostCore and EaglerXServer) concealed in the platform's file manager were found to be fully accessible via standard user SFTP - a further exposure of server-side infrastructure.

No Hacking Required

All endpoints were accessible using nothing more than a standard session cookie from a free account. This is not a sophisticated exploit - it is a complete absence of access control on administrative API routes.

What Was Exposed

📧

Email Addresses

Every verified email on the platform. 100% of accounts had emailVerified = true.

👤

Usernames and IDs

All usernames and 8-character hex account identifiers - cross-referenceable across both databases.

💳

Credit Balances

Live transactional credit balances on all accounts, updating in real time.

🖥

Live Server Infrastructure

20,564 records including 64-char Docker container IDs, live ports, and real-time resource stats.

Activity Timestamps

Account creation dates, last login, and full server start history for every user.

⚙️

JVM Configuration

Internal Java startup flags, memory tier requirements, and GC tuning for all server versions.

Key Events

All times are UTC+1 (CET), as shown in preserved Discord screenshots filed with the ICO.

7 March 2026 - 13:52 UTC+1
Breach Discovered and Reported
Snelsterendier discovers the unauthenticated endpoints and contacts TopEaglerServers via Discord immediately, disclosing in good faith.
7 March 2026 - 14:06 UTC+1
Controller Acknowledges Breach in Writing
Staff member Josh responds: "Thank you for letting us know. We are working on a fix right now." The 72-hour ICO notification clock begins (12:54 UTC).
7 March 2026 - 14:46-14:49 UTC+1
Controller Denies Legal Obligations
When Snelsterendier raises GDPR, Josh claims the law doesn't apply - verbatim quotes preserved in the ICO complaint. See Response section.
7 March 2026 - 15:17-15:20 UTC+1
Fix Deployed but Confirmed Ineffective
Josh asks Snelsterendier to verify. The endpoints remain accessible at 15:20. No further technical update was ever provided.
8 March 2026 - 13:07 UTC+1
No Statement. No Response.
Snelsterendier asks if a statement will be issued. TopEaglerServers does not reply. No communication received from them since 7 March.
10 March 2026 - 12:54 UTC
72-Hour ICO Notification Deadline Expires
The legally required notification window closes. Zero users have been notified. No ICO report filed by the Controller.
10 March 2026
Formal ICO Complaint Submitted
A full formal complaint with verbatim evidence is submitted to the Information Commissioner's Office by @snugent120 on behalf of Snelsterendier.

Children's Data Was Exposed

The exposed user database contains a significant number of K-12 school-issued email addresses. These are government-issued institutional addresses - there is no plausible non-educational interpretation. These users are students, very likely minors.

The following domains were identified in the data sample alone - less than 0.2% of the full 27,611-record dataset.

DomainInstitutionLocation
dallasisd.orgDallas Independent School DistrictTexas, USA
online.houstonisd.orgHouston Independent School DistrictTexas, USA
lakesideusd.orgLakeside Unified School DistrictCalifornia, USA
students.bentonschools.orgBenton School DistrictArkansas, USA
brssd.orgBelmont-Redwood Shores School DistrictCalifornia, USA
student.uplifteducation.orgUplift Education Charter SchoolsTexas, USA
msd19.orgMalheur School District 19Oregon, USA
methow.orgMethow Valley School DistrictWashington, USA
albany.k12.ny.usAlbany City School DistrictNew York, USA
myoneclay.comClay County District SchoolsFlorida, USA
masonohioschools.comMason City School DistrictOhio, USA
edu.leonschools.netLeon County SchoolsFlorida, USA
student.vigoschools.orgVigo County School CorporationIndiana, USA
hcarockwall.orgHeritage Christian AcademyTexas, USA
student.smusd.usSan Marcos Unified School DistrictCalifornia, USA
Legal Implications

Children's data attracts heightened obligations under Article 8 UK GDPR, the ICO's Age Appropriate Design Code, and US federal law including COPPA (15 U.S.C. Section 6501 et seq.). TopEaglerServers implemented no meaningful age verification and has taken no steps to protect or notify the children whose data was exposed.

How TopEaglerServers Responded

When Snelsterendier raised UK GDPR obligations at 14:28 UTC+1 on 7 March 2026, staff member Josh issued the following responses - preserved verbatim and submitted as evidence to the ICO:

Josh - 14:46, 7 March 2026 (UTC+1)
"We aren't European so that law doesn't apply to us but we'll still investigate and resolve this issue."

Snelsterendier immediately corrected this. Josh then added:

Josh - 14:49, 7 March 2026 (UTC+1)
"We aren't a registered business and don't target EU residents."

Both claims are legally incorrect and contradicted by TopEaglerServers' own documents:

⚖️

"Not European"

UK GDPR applies based on the location of data subjects, not the controller's nationality. Their own Terms of Service states the platform is governed by UK law.

📋

"Not a Registered Business"

UK GDPR and the DPA 2018 apply to natural persons processing others' data - corporate status is irrelevant.

🔐

Privacy Policy Promise Broken

Their own Privacy Policy states: "we will notify you in a timely manner, as required by applicable laws." Not honoured.

Action Taken

Formal ICO Complaint Submitted - 10 March 2026

A full formal complaint has been submitted to the Information Commissioner's Office (ICO) by @snugent120 on behalf of Snelsterendier. The complaint includes verbatim evidence of the GDPR denials, full breach disclosure, and a confirmed record of the Controller's total inaction. The ICO can investigate, issue enforcement notices, and impose penalties of up to £17.5 million or 4% of global turnover.

Because TopEaglerServers refused to notify any of its 27,611 users, @snugent120 and Snelsterendier initiated an independent notification campaign across Discord communities frequented by the Eaglercraft player base - performing the function the Controller is legally required to fulfil under Article 34 UK GDPR.

GDPR Articles Violated

ArticleViolation
Art. 5(1)(f)Integrity and confidentiality - no access control on admin API routes
Art. 32Security of processing - complete absence of appropriate technical measures
Art. 3372-hour notification to supervisory authority - missed entirely
Art. 34Communication to data subjects - zero users notified
Art. 5(1)(a)Lawfulness, fairness, transparency - Privacy Policy promise broken
Art. 5(1)(c)Data minimisation - excessive technical data retained and exposed
Art. 8Children's consent - no age verification or parental consent mechanism
Art. 13/14Transparency - controller actively misrepresented its legal obligations

What You Should Do

If you have ever registered on topeaglerservers.com, your email address and account data were exposed.

Follow the Investigation on Discord

Join our server for live updates, new findings, and to connect with others affected by this breach.

Join Discord

Thanks To

This disclosure and investigation would not have been possible without the following - who gave their time to ensure 27,611 people were not left in the dark.

Vulnerability Finder and Organizer
@Snelsterendier

For discovering the vulnerability, disclosing it responsibly, and having the integrity to ensure it was taken further when the platform refused to act. The entire process started here.

Broadcaster
@Colbster937

For helping spread awareness of this breach across Discord communities and ensuring affected users were reached directly.

Broadcaster
@EclipseShadow

For helping spread awareness of this breach across Discord communities and ensuring affected users were reached directly.

Legal and Broadcaster
@Snugent120

For compiling and submitting the formal ICO complaint, ensuring the Controller's inaction is on regulatory record, and broadcasting the disclosure widely.

Vulnerability Finder and Site
@DataDecay

For independently identifying vulnerabilities and working on the site - more to come soon.

Documentator
@malindiboys.

For documenting the breach, evidence, and timeline - ensuring everything was recorded accurately for the public record and the ICO complaint.