Catalin Cimpanu reports: Attunity, an Israeli IT firm that provides data management, warehousing, and replication services for the world’s biggest companies, has exposed some of its customers’ data after it left three Amazon S3 buckets exposed on the internet without a password. The leaky AWS S3 buckets contained information on Attunity’s own operations, but also…
Category: Exposure
5 million personal records belonging to MedicareSupplement.com exposed to public
Paul Bischoff writes: An online database of more than 5 million records apparently belonging to MedicareSupplement.com was left open and accessible to the public. On May 13, 2019, Comparitech worked alongside security researcher Bob Diachenko to uncover the publicly available MongoDB instance that appears to be part of the website’s marketing leads database. MedicareSupplement.com is…
WeTransfer Security Incident Sent Files to the Wrong People
Lawrence Abrams reports: In an embarrassing security incident, the WeTransfer file sharing service announced that for two days it was sending it’s users shared files to the wrong people. As this service is used to transfer what are considered private, and potentially sensitive files, this could be a big privacy issue for affected users. Starting…
Insurance company AIA fined $10,000 by PDPC for personal data breach
Lester Wong reports from Singapore: Insurance company AIA was fined $10,000 by the Personal Data Protection Commission (PDPC) for mistakenly sending 245 letters meant for various customers to just two people due to a programming error in its software system that auto-generates the letters. The bulk of the letters (237) were premium notice letters for…
Email gaffes are still a thing. Why? HIV patients hit by NHS Highland email privacy breach
BBC reports: The email addresses of almost 40 people who have HIV have been made public by mistake. It is understood the 37 patients in the Highlands were able to see their own and the others people’s addresses in an email from NHS Highland. Read more on BBC.
Parliament chiefs investigate claims its website was hacked amid fears of confidential data breach
Matt Dathan reports: The site containing bills currently before Parliament was showing private folders not meant for publication. One Twitter user said they had found passwords had leaked online too. A Parliamentary spokesman said it was looking into the reports but said it had not found any evidence that confidential parliamentary data had been breached….