An unsecured FedEx server was breached,Watch The Tax Collector Online exposing thousands of customers' personal information, a prominent security research firm discovered earlier this month.
Package forwarding service Bongo International was acquired by FedEx in 2014 and now serves as a e-commerce service called FedEx Cross Border.
But an unsecured Amazon S3 server, according to the white hat research group Kromtech, was holding more than 100,000 scanned documents including passports, drivers licenses, and security IDs. The white hat group responsibly disclosed the breach.
SEE ALSO: Olympic organizers hit with hack during opening ceremonyIn a statement a FedEx spokesperson said the server has since been secured, and the data wasn't "misappropriated." The full statement reads:
After a preliminary investigation, we can confirm that some archived Bongo International account information located on a server hosted by a third-party, public cloud provider is secure. The data was part of a service that was discontinued after our acquisition of Bongo. We have found no indication that any information has been misappropriated and will continue our investigation.
Kromtech was able to get in touch with FedEx through a reporter earlier this week and secure the compromised data. This likely means anyone whose information was housed in that server is safe.
Alex Heid, white hat hacker and chief research officer at SecurityScorecard, said in a call it's very likely none of the data was used, but it was sitting there for a long time. "Thankfully this group was working to report that type of stuff," unlike the Equifax breach last year where the information was used maliciously.
He said this type of information leak is "incredibly common" as "new big data technologies become easier to use," but companies don't necessarily know how to use and secure them, like this Amazon S3 server forgotten in an years-old acquisition.
He said FedEx shouldn't be judged for having the data open, but on how they react to the exposure. "It’s a matter of having a program in place when it happens," Heid said.
Topics Cybersecurity
(Editor: {typename type="name"/})
Best robot vacuum deal: Save $350 on the Eufy X10 Pro Omni
Investigation reveals that Australians didn't vote for Ferry McFerryface
YouTube TV comes to Roku boxes
Mozilla updates Firefox Quantum to fix huge security vulnerability
AC Milan vs. Feyenoord 2025 livestream: Watch Champions League for free
Apple responds to U.S. government's investigation over slow iPhones
Former Fox News host says Roger Ailes secretly watched female employees 'disrobe'
An ode to the delightfully unhinged Lisa Frank Facebook page
Biggest Tech Fads of the Last Decade
Little girl found the creepiest sock and shoe combination imaginable
SpaceX is so close to turning its rocket headquarters into an actual city
Instagram adds a feature for brands, still no chronological timeline
接受PR>=1、BR>=1,流量相当,内容相关类链接。