// data security

All signals tagged with this topic

Exposed Passport Database Highlights ID Verification Infrastructure Gaps

A misconfigured cloud storage bucket exposed nearly a million identity documents. The incident reflects a broader problem: biometric and identity verification vendors operating at the infrastructure layer of digital onboarding often treat security as secondary to deployment speed. Companies handling government-issued credentials apply less rigor than financial services would demand, even as digital identity becomes the gating layer for financial services, hiring platforms, and government access globally. The vulnerability isn't encryption or hacking—it's the proliferation of unvetted third-party identity platforms that enterprises trust without understanding their security posture.

Hotel check-in system exposed a million travel documents to the internet

A misconfigured cloud storage bucket—the most common form of data exposure in hospitality—shows that routine operational infrastructure (hotel registration systems) now holds identity verification data that criminals actively harvest for fraud. The system was public by default, meaning the vulnerability required zero technical skill to exploit and likely persisted for months before discovery. Hotels appear to lack basic audit practices for third-party vendors handling biometric and document data.