A Duc App data exposure has compromised the personal information of thousands of fintech users. Security researchers recently identified a publicly accessible Amazon-hosted storage server belonging to Duales, the Toronto-based operator of the Duc App money-transfer service. This infrastructure misconfiguration left sensitive identity verification documents entirely unprotected on the open internet.
The Duc App data breach centers on the sensitive nature of the unencrypted information exposed. CyPeace cybersecurity researcher Anurag Sen discovered that the database contained over 360,000 files used for mandatory "know your customer" (KYC) protocols, according to TechCrunch.
Several folders each contained “tens of thousands” of user-uploaded files and detailed spreadsheets, including:
Because the data lacked encryption, anyone possessing the easy-to-guess web address could view and download the contents in plaintext.
Operating an unprotected Amazon-hosted storage server presents severe user data security risks, especially for a financial application boasting over 100,000 downloads. Duales Chief Executive Henry Martinez González stated the infrastructure functioned as a "staging site," and the company subsequently restricted access to the files.
This Duales data exposure adds to several other cases of cloud misconfigurations, reminding financial institutions that failing to implement basic access controls can severely impact consumer privacy and compromise operational integrity.
Last year, misconfigurations across seven cloud providers exposed 660,000 buckets, 200 billion files, 110,000 credentials, and more.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
