14M Verizon customer records found on publicly available server

Shutterstock

Data belonging to at least 6 million Verizon subscribers were exposed due to a security lapse by one of the carrier's customer service partners. Nice Systems (as a partner/third-party vendor) would have had natural access to this information, given their software was being used to provide back-office support to Verizon.

Nice Systems says that the exposed data was "part of a system demo" with no further elaboration.

The security firm said the files were discovered on an unprotected Amazon Web Services (AWS) database on 8 June but that the issue was not fully resolved until weeks later, on 22 June 2017.

Chris Vickery is the researcher at UpGuard who first discovered the leak.

Verizon data has been leaked online and this data breach involved 6 million users.

Verizon, the USA telecommunications juggernaut, has admitted that the data of at least six million of customers, including names, addresses, account details and account PIN numbers, were exposed online.

The leak happened when a NICE Systems employee put customer data into a cloud storage area and accidentally made it publicly accessible, instead of private. Verizon confirmed that information was at risk of being comprised, and said human error was the reason for the potential leak.

Hackers will be able to use the PIN codes to easily gain access to online accounts that are protected by two-factor authentication, which is a security measure that confirms the actions of users by sending a code to their mobile phone number. "The long duration of time between the initial June 13th notification to Verizon by UpGuard of this data exposure, and the ultimate closure of the breach on June 22nd, is troubling".

"A misconfigured cloud-based file repository exposed the names, addresses, account details, and account personal identification numbers (PINs) of as many as 14 million U.S. customers of telecommunications carrier Verizon, per analysis of the average number of accounts exposed per day in the sample that was downloaded".

Upguard added in its assessment of the breach: "This exposure is a potent example of the risks of third-party vendors handling sensitive data". If they have those, they can change devices associated with the phone numbers of the account, thereby hijacking those phone numbers, or make fraudulent purchases through customer service. "Typically, the bad actor ports the number to some sort of virtual number, but there have been cases where the number is ported to a burner phone".

"Cyber risk is a fact of life for any digital service".

Related news:

Hot News

isis-killer-beheading-video-story-top 3 takeaways from Kentavious Caldwell-Pope deal
Jul 13, 2017 - 00:22
If the things work out the way both sides are hoping to, Caldwell-Pope might be in Lakers uniform for more than one season. Nwaba had been playing in Summer League with the Lakers , showing fortitude as one of the team's strongest players.

isis-killer-beheading-video-story-top Wimbledon: Venus Williams becomes oldest female semifinalist in 23 years
Jul 13, 2017 - 00:17
Ostapenko keeps hoper alive of progressing as she manages to hold her serve and make it 3-2 in the second set. But her aggressive, risk and reward game came unstuck against the powerful Williams serve.

isis-killer-beheading-video-story-top Taylor report calls for greater protection for gig economy workers
Jul 12, 2017 - 00:11
At the moment, there is a middle ground status, "worker", between self-employed and fully employed in employment law . The U.K. government is trying to improve working conditions for contract workers participating in the "gig economy".

isis-killer-beheading-video-story-top Gopal Krishna Gandhi named opposition's candidate for Vice President's election
Jul 12, 2017 - 00:11
The Opposition has chosen Gopalkrishna Gandhi as its nominee for the upcoming vice-presidential election, sources told PTI . He also served as High Commissioner to South Africa in 1996, where he earned a popular repute, as reported by the Outlook.

isis-killer-beheading-video-story-top Bull Run Continues On Dalal Street; Sensex, Nifty Settle At Record Highs
Jul 11, 2017 - 00:20
Mumbai: Markets continued their upward climb in afternoon trade with both Sensex and Nifty peaking a fresh all-time highs. The technical team of NSE is looking into the issue and market re-open time would be intimated shortly, it had said.

isis-killer-beheading-video-story-top Parents still fighting for Charlie Gard's treatment
Jul 11, 2017 - 00:09
The official also said the president wants to be helpful without placing undue pressure on the family. He said seven global experts had supported the treatment the couple wanted Charlie to have.

isis-killer-beheading-video-story-top USA 'must fix the many bad trade deals it has made'
Jul 10, 2017 - 00:20
So despite some compromises, the US still has a mechanism to declare a trade war over steel at any time. Trump announced Friday that had called on South Korea to "stop enabling the export of dumped steel".

isis-killer-beheading-video-story-top F1 Bottas - victor of pole position in Austria
Jul 09, 2017 - 00:28
Vettel is on the front row and teammate Kimi Raikkonen moves up from fourth to third because of Hamilton's grid demotion. In fact, Hamilton was quicker than Bottas in every single session through the weekend top 10 qualifying shoot-out.

isis-killer-beheading-video-story-top Illinois Capitol Placed on Lockdown for About 2 Hours
Jul 08, 2017 - 00:10
The investigation has delayed Thursday's critical override vote on a package of bills that could end the state's budget impasse. Mitchell said the vote for a tax increase was the most hard he had taken in his 18 years as a legislator.

isis-killer-beheading-video-story-top Blac Chyna's Attorney Exploring Legal Options Against Rob Kardashian
Jul 07, 2017 - 00:33
In response to these allegations, Blac taunted Rob with the $250k worth of jewelry, he gave her on the day he caught her cheating. Rob Kardashian went on a social media tirade against his on again, off again girlfriend, Blac Chyna on Wednesday, July 5.

isis-killer-beheading-video-story-top Fire forces hundreds of evacuations in Colorado
Jul 07, 2017 - 00:29
At a media briefing Wednesday it was announced that a Type 1 Incident Management Team would arrive at the fire on Thursday. Around 2 this afternoon the fire was spreading quickly --so they decided it was necessary to order those evacuations.

isis-killer-beheading-video-story-top Charlie Gard's future should be decided by doctors, Boris Johnson says
Jul 06, 2017 - 00:13
Boris Johnson has insisted that Charlie Gard's future should be decided by "expert medical opinion" and supported by the courts. Eleven-month-old Charlie Gard has irreversible brain damage and can not see, hear, move or even cry, doctors say.

isis-killer-beheading-video-story-top India 'misleading the public' on Sikkim standoff: China
Jul 06, 2017 - 00:13
Under Chinese leader Xi Jinping , China has been more assertive in insisting neighbours accept Beijing's "zone of influence". "And there is no dispute between the two countries that Doklam belongs to China", he stated.

isis-killer-beheading-video-story-top Fed minutes suggest increasing tensions on inflation shortfall
Jul 06, 2017 - 00:05
Investors also see the next rate increase occurring in December, according to Fed funds futures data compiled by the CME Group. The reductions would begin this year "provided that the economy evolves broadly" as Fed officials are forecasting, she said.

isis-killer-beheading-video-story-top China's Xi Warns Trump about 'Negative' Parts of Relationship
Jul 05, 2017 - 00:08
When Trump and Xi met in April, the two leaders agreed to take specific steps against North Korea within the next 100 days. The U.S. has dreaded the day that North Korea developed a missile capable of hitting the homeland with a nuclear warhead.