Thousands Of British Passports Left Exposed On Unsecured AWS Bucket

It has been reported that an unsecured database on Amazon has been discovered, exposing sensitive information and passport scans on thousands of employees. The information, including thousands of passport scans, tax documents, background checks, job applications, expense forms, scanned contracts, emails, and salary details, was stored on an Amazon Web Services (AWS) S3 bucket. The unencrypted database was exposed for an unknown amount of time impacting consultancy firms such as Garraway Consultants, Dynamic Partners, IQ Consulting, Eximius Consultants Limited, Winchester Ltd, Partners Associates Ltd, and others. While many of these firms are no longer in business, the exposed PII still relates to existing people who could be at risk.


EXPERTS COMMENTS
Richard Walters, CTO ,  Censornet
January 16, 2020
This is not the fault of Amazon, which has security measures for its AWS storage.
Another day, another unsecured AWS bucket, and the data in this one couldn't be more sensitive. The files discovered by the researchers include passports, job applications, tax documents, background checks, and scanned contracts. Essentially, every personal detail a criminal could possibly need to conduct identify theft, all left in an unsecure database online. The oldest of the UK information dat ....
[Read More >>]
Javvad Malik, Security Awareness Advocate,  KnowBe4
January 16, 2020
Cloud adoption has enabled many companies to conveniently gather and store large amounts of data.
Cloud adoption has enabled many companies to conveniently gather and store large amounts of data. However, just because the cloud provider secures the infrastructure, it doesn't mean the data is automatically secured. It still remains the responsibility of the cloud service user to ensure that all data that is collected is properly secured. With the large number of unsecured AWS S3 buckets expos ....
[Read More >>]
Boris Cipot, Senior Sales Engineer ,  Synopsys
January 16, 2020
This is especially true when passport details, salary information and other pieces of sensitive data are being handled.
Cloud storage solutions are convenient and cost effective. It’s also of great importance to remember that every implementation of such services need to be handled by experts who understand how to configure S3 buckets securely. This is especially true when passport details, salary information and other pieces of sensitive data are being handled. In these scenarios, organizations must follow certa ....
[Read More >>]
Jonathan Deveaux, Head of Enterprise Data Protection,  comforte AG
January 16, 2020
Technology professionals really need to get out of the habit of leaving sensitive data unprotected.
What may be most revealing about this sensitive data discovery, is that many of the firms are no longer in business. If one of the people were negatively affected by this data exposure discovery, and they want to hold someone, or some organization responsible, who would that be? Company policies towards sensitive data need to ensure sensitive data is protected at all times, which would minimize ....
[Read More >>]

If you are an expert on this topic:

Dot Your Expert Comments

SUBSCRIBE to alert when new comments are posted on this news. :




In this article