Securityaffairs.Co
Misconfigured Cloud Storage Exposes Over 1 Million IDs from Tabiq Hotel System
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A misconfigured Amazon cloud storage bucket exposed over one million passports, driver's licenses, and selfies from the Tabiq hotel check-in system, maintained by Reqrea, a Japanese startup. The data was publicly accessible due to the bucket being set to open access, allowing anyone to view the sensitive documents without authentication. Independent researcher Anurag Sen discovered the leak and alerted TechCrunch, which subsequently notified Reqrea and Japan's cybersecurity team, JPCERT. The exposed data included identity documents dating back to early 2020. Reqrea has since secured the bucket and is investigating the incident to assess the scope of exposure and determine if unauthorized access occurred. The company plans to notify affected individuals once the investigation is complete. This incident highlights ongoing issues with basic cybersecurity practices leading to significant data exposure.
Key Points: • Over 1 million sensitive documents were exposed due to a misconfigured cloud storage bucket. • The data leak was discovered by an independent researcher and reported to TechCrunch. • Reqrea has secured the exposed data and is conducting an investigation into the incident.