cloud

Over 750,000 U.S Birth Certificate Applications Exposed Online From Unsecured AWS bucket

Over 750,000 birth and death certificate applications exposed online from unsecured Amazon Web Services cloud bucket. The data exposed online by an unknown company that supplies data to state governments.

The unsecured bucket was discovered by U.K.-based cybersecurity company Fidus Information Security. The bucket has no password protection, anyone with the link can access the records.

The bucket found to be created in 2017 and the bucket was updated daily, “In one week, the company added about 9,000 applications to the bucket,” reads Techcrunch post.

The exposed data includes the following data such as “name, date of birth, current home address, email and phone number, names of family members, historical information (i.e. addresses), or the reason behind applying for the documents.”

Techcrunch was able to verify the integrity of the data by matching names and addresses against public records.

The company name was not revealed, Fidus and TechCrunch attempted to reach the company via email but no response, they reached Amazon “said it would inform the customer.”

Amazon S3 is one of the leading cloud storage solutions it was launched in 2006, you can store any data with the S3 buckets.

The Amazon S3 buckets leak became prominent now as several companies suffered the leak, the most common cause for the data leak is the misconfigured security settings. Amazon has introduced several security updates to protect the buckets, but still misconfigured S3 buckets exist.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates

Also Read

Hospital in New York Hacked with Ransomware – Permanently Lost the Patient Records

Hospitality Company OYO Exposes Millions of Customer Data

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago