Top auto insurance firm leaked over 5 million records


ClaimPix, a company which streamlines car insurance claims, was leaking sensitive customer data on the clearweb, including people’s phone numbers, and email addresses, an expert has warned.

Security researcher Jeremiah Fowler, known for hunting down misconfigured and unprotected databases, recently found one such instance containing 5.1 million files, sharing his findings with WebsitePlanet. The archive was 10TB in size, and included documents such as power of attorney, vehicle registration, estimates, repair invoices, and images of damaged vehicles with visible license plates and VIN numbers.

Read more…
Source: TechRadar News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Thousands of U.S. Voter Personal Records Leaked by Robocall Firm

    July 18, 2018

    The information was exposed on a public Amazon S3 bucket by a Virginia-based political campaign and robocalling company. Researchers have discovered yet another misconfigured repository bucket – this time leaking the information of U.S. voters. The information was exposed on a public Amazon S3 bucket by a Virginia-based political campaign and robocalling company called Robocent. Kromtech Security researchers, ...

  • Indictments Against 12 Russians Show How Hackers Were Hacked

    July 18, 2018

    Hi everybody, Jordan Robertson here. I cover cybersecurity in Washington, D.C. Today’s newsletter is about Special Counsel Robert Mueller’s indictment this week of 12 Russian military officers for allegedly orchestrating the hacks of the 2016 U.S. presidential election. The indictment, which I encourage you to read if you’re interested in technical details about how the hacks worked, is remarkable in a number ...

  • Hacker Sold Stolen U.S. Military Drone Documents On Dark Web For Just $200

    July 11, 2018

    You never know what you will find on the hidden Internet ‘Dark Web.’ Just about an hour ago we reported about someone selling remote access linked to security systems at a major International airport for $10. It has been reported that a hacker was found selling sensitive US Air Force documents on the dark web for between $150 ...

  • White House picks new chief to oversee cyber-weapons group

    June 22, 2018

    The White House has a new leader of a largely secretive government group that decides whether software and hardware vulnerabilities should be withheld from the public to help the government conduct cyber operations. Grand Schneider, the federal chief information security officer and senior director at the National Security Council, was named head of the Vulnerabilities Equities Process (VEP) ...

  • GDPR: US news sites blocked to EU users over data protection rules

    May 25, 2018

    A number of high-profile US news websites are temporarily unavailable in Europe after new European Union rules on data protection came into effect. The Chicago Tribune and LA Times were among those posting messages saying they were currently unavailable in most European countries. The General Data Protection Regulation (GDPR) gives EU citizens more rights over how their ...

  • U.S. raises concerns about Vietnam’s proposed cybersecurity law

    May 24, 2018

    The United States has raised concerns with Vietnam about its proposed cybersecurity law, the U.S. Embassy said on Thursday, amid activists’ fears the new legislation will cause economic harm and crackdown on online dissent in the communist-ruled country. The concerns were conveyed by Deputy U.S. Trade Representative Jeffrey Gerrish in a meeting with Vietnam’s Deputy Prime ...