Securityaffairs.Co Misconfigured Cloud Storage Exposes Over 1 Million IDs from Tabiq Hotel System
Article Content
- •Over 1 million sensitive documents were exposed due to a misconfigured cloud storage bucket.
- •The data leak was discovered by an independent researcher and reported to TechCrunch.
- •Reqrea has secured the exposed data and is conducting an investigation into the incident.
A misconfigured Amazon cloud storage bucket exposed over one million passports, driver's licenses, and selfies from the Tabiq hotel check-in system, maintained by Reqrea, a Japanese startup. The data was publicly accessible due to the bucket being set to open access, allowing anyone to view the sensitive documents without authentication. Independent researcher Anurag Sen discovered the leak and alerted TechCrunch, which subsequently notified Reqrea and Japan's cybersecurity team, JPCERT. The exposed data included identity documents dating back to early 2020. Reqrea has since secured the bucket and is investigating the incident to assess the scope of exposure and determine if unauthorized access occurred. The company plans to notify affected individuals once the investigation is complete. This incident highlights ongoing issues with basic cybersecurity practices leading to significant data exposure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Duc App in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…