Press release: "A sophisticated cyberattack has breached our system. Although we assure you that no public data was accessed, we are advising those who have traveled within the last 10 years to assume a new identity."
My money is on a unprotected Elasticsearch server.
Definitely a password-less, Internet facing MongoDB instance.
How else will you get web scale security breaches?
Unprotected MongoDB with committed writes turned off
I agree that is very likely these days, but the laptop thing has happened before [1]