A US-based company that allows people to apply for a copy of their birth certificates used unprotected Amazon Web Service cache that allowed access to anyone.
Recently, security researchers from a company known as Fidus Information Security discovered an unprotected cache containing applications of birth certificate applications belonging to over 750,000 US citizens. The cache belongs to a US-based company that allows people to obtain a copy of their own birth certificates.
The applications were discovered on an Amazon Web Services cache, and they were left unprotected, without even a password guarding them. Fidus Information Security reveals that simply entering an address of the cache, which was relatively easy to guess, anyone could have gained access to these applications and documents.
The findings were confirmed by TechCrunch, which published the reveal in its own report. However, both TechCrunch and Fidus Information Security decided not to reveal the name of the negligent firm that owns the cache.
https://twitter.com/zackwhittaker/status/1204099138150752256
When it comes to the exposed information, it included various personal details such as the applicant’s name, address, email, phone number, as well as their date of birth. Apart from that, the information included numerous other details regarding the applicants, such as family members’ names, their previous address, and even their reason for wanting a copy of their birth certificates.
The reports claim that the exposed applications go back for about two years, to 2017. There were an estimated 9,000 individual applications that were added per day from the moment TechCrunch joined the investigation.
In addition, the cache also included 90,400 death certificates, although these were protected in a way that prevented TechCrunch from obtaining them.

Images are courtesy of Twitter, Shutterstock.
Disclaimer
All the information contained on our website is published in good faith and for general information purposes only. Any action the reader takes upon the information found on our website is strictly at their own risk.
Sponsored
Sponsored