TechCrunch News 01月03日
Online gift card store exposed hundreds of thousands of people’s identity documents
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

一家美国在线礼品卡商店的服务器未设密码,导致数十万客户的身份证明文件在互联网上公开暴露。这些文件包括驾照、护照等,属于MyGiftCardSupply公司,该公司要求客户上传身份证明以遵守反洗钱法规。安全研究员JayeLTee发现了这一漏洞,并在公司未回应的情况下向媒体曝光。MyGiftCardSupply已确认安全漏洞,并表示已修复并进行审计,但未透露数据暴露时长,也未承诺通知受影响用户。暴露的数据包括超过60万份身份证明图像和约20万用户的自拍照,托管在微软Azure云上。这并非首次发生此类事件,此前也出现过涉及KYC检查的身份文件泄露事件。

🔑 MyGiftCardSupply公司为遵守反洗钱法规,要求客户上传身份证明文件,但存储服务器未设密码,导致数据泄露。

📸 泄露数据包含超过60万份身份证明文件正反面图像和约20万用户的自拍照,这些文件被托管在微软Azure云平台上。

⚠️ 公司创始人虽确认漏洞并修复,但未说明数据暴露时长,也未承诺通知受影响用户,同时对为何未回应研究员邮件保持沉默。

🚨 此事件并非个例,此前已发生多起涉及KYC检查的身份信息泄露事件,表明该领域存在普遍的安全风险。

🔎 安全研究员JayeLTee还发现了另一家公司Roomster也存在类似的KYC文件泄露问题,涉及约32万份护照和驾照。

A U.S. online gift card store has secured an online storage server that was publicly exposing hundreds of thousands of customer government-issued identity documents to the internet.

A security researcher, who goes by the online handle JayeLTee, found the publicly exposed storage server late last year containing driving licenses, passports and other identity documents belonging to MyGiftCardSupply, a company that sells digital gift cards for customers to redeem at popular brands and online services. 

MyGiftCardSupply’s website says it requires customers to upload a copy of their identity documents as part of its compliance efforts with U.S. anti-money laundering rules, often known as “know your customer” checks, or KYC.

But the storage server containing the files had no password, allowing anyone on the internet to access the data stored inside.

JayeLTee alerted TechCrunch to the exposure last week after MyGiftCardSupply did not respond to the researcher’s email about the exposed data.

When reached by TechCrunch, MyGiftCardSupply founder Sam Gastro confirmed the security lapse. “The files are now secure, and we are doing a full audit of the KYC verification procedure,” said Gastro. “Going forward, we are going to delete the files promptly after doing the identity verification.” 

Gastro would not say how long the data was exposed to the internet, nor would the company commit to notifying affected individuals whose information was left public. Gastro also did not address why MyGiftCardSupply did not reply to the researcher’s email or remediate the security lapse at the time.

According to JayeLTee, the exposed data — hosted on Microsoft’s Azure cloud — contained over 600,000 front and back images of identity documents and selfie photos of around 200,000 customers. It’s not uncommon for companies subject to KYC checks to ask their customers to take a selfie while holding a copy of their identity documents to verify that the customer is who they say they are, and to weed out forgeries.

The most recent uploaded document on the server was dated December 31, 2024, a day before MyGiftCardSupply secured the exposed server. Thousands of customers uploaded their identity documents in the preceding weeks, suggesting the storage server was actively used.

This is the latest in a long list of incidents and data breaches in recent years involving identity documents for KYC checks, which remains one of the most relied-upon techniques for verifying a customer’s identity. 

Last April, a hacker claimed to have stolen a massive screening database called World-Check, a database used by companies to determine if customers are high risk or involved in potential criminality. A copy of the leaked data showed the database contained names, dates of birth, passport and Social Security numbers, and bank account numbers.

JayeLTee separately reported on Thursday finding another cache of exposed KYC documents, including around 320,000 passports and driver’s licenses, from roommate finding site Roomster.

In a blog post, JayeLTee said it was not clear exactly how many individuals were affected by the security lapse at Roomster, and its CEO John Shriber did not return TechCrunch’s email requesting comment. Roomster was in 2023 ordered to pay $1.6 million following a Federal Trade Commission complaint for allegedly defrauding millions of its users by posting unverified listings and fake reviews.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

数据泄露 身份信息 KYC 安全漏洞 隐私保护
相关文章