Misconfigured Cloud Storage Exposes Over 1 Million IDs from Tabiq Hotel System

Misconfigured Cloud Storage Exposes Over 1 Million IDs from Tabiq Hotel System

First seen 18 May 2026, 13:48 UTC TechcrunchSecurityaffairs.Co 76% similarity 64.5

Article Content

Browse articles
ThreatCluster

A misconfigured Amazon cloud storage bucket exposed over one million passports, driver's licenses, and selfies from the Tabiq hotel check-in system, maintained by Reqrea, a Japanese startup. The data was publicly accessible due to the bucket being set to open access, allowing anyone to view the sensitive documents without authentication. Independent researcher Anurag Sen discovered the leak and alerted TechCrunch, which subsequently notified Reqrea and Japan's cybersecurity team, JPCERT. The exposed data included identity documents dating back to early 2020. Reqrea has since secured the bucket and is investigating the incident to assess the scope of exposure and determine if unauthorized access occurred. The company plans to notify affected individuals once the investigation is complete. This incident highlights ongoing issues with basic cybersecurity practices leading to significant data exposure.

Key Points: • Over 1 million sensitive documents were exposed due to a misconfigured cloud storage bucket. • The data leak was discovered by an independent researcher and reported to TechCrunch. • Reqrea has secured the exposed data and is conducting an investigation into the incident.

ThreatCluster AI

Timeline

2026-05-15
TechCrunch reports data exposure
TechCrunch published an article detailing the exposure of over 1 million sensitive documents from Tabiq due to a misconfigured cloud storage bucket.
Techcrunch
2026-05-15
Reqrea secures the storage bucket
After being notified by TechCrunch, Reqrea secured the misconfigured Amazon storage bucket to prevent further access to the exposed data.
Techcrunch
2026-05-18
Security Affairs reports on the incident
Security Affairs published an article summarizing the exposure and its implications for cybersecurity practices.
Securityaffairs.Co

Community

Browse all →

Tracked Entities in This Story