{"id":25507,"date":"2024-11-28T08:10:22","date_gmt":"2024-11-28T16:10:22","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2024\/11\/28\/news-19237\/"},"modified":"2024-11-28T08:10:22","modified_gmt":"2024-11-28T16:10:22","slug":"news-19237","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/11\/28\/news-19237\/","title":{"rendered":"Data broker exposes 600,000 sensitive files including background checks"},"content":{"rendered":"\n<p>A researcher has <a href=\"https:\/\/www.websiteplanet.com\/news\/propertyrecs-breach-report\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">discovered<\/a> a data broker had stored 644,869 PDF files in a publicly accessible cloud storage container.<\/p>\n<p>The 713.1 GB container (an Amazon S3 bucket\u00a0) did not have password-protection, and the data was left unencrypted, so anybody who stumbled on them could read the files. The files not only contained thousands of people&#8217;s vehicle records (license plate and VIN) and property ownership reports, but also criminal histories, and background checks.<\/p>\n<p>The majority of the records were labelled as background checks which contained full names, home addresses, phone numbers, email addresses, employment history, family members, social media accounts, and criminal record history.<\/p>\n<p>Data brokers collect and sell your information, including financial, personal, behavior and interests, for profit. SL Data Services <a href=\"https:\/\/www.sldataservices.com\/\">markets itself<\/a> as a provider of real estate information reports. But when the researcher contacted its support team, they stated the company also provides criminal checks, division of motor vehicles (DMV) records, death and birth records.<\/p>\n<p>Probably to organize the data to this end, the folders inside the container all had names of separate website domains. The company apparently operates a network of an estimated 16 different websites, offering a range of information services (e.g. <a href=\"https:\/\/www.propertyrec.com\/\">PropertyRec<\/a>).<\/p>\n<p>Background checks can and are often done without the subject\u2019s awareness. But with all the combined information about a person, it paints a very complete picture that insurance companies, advertisers, and even cybercriminals can use to their advantage.<\/p>\n<p>The researcher explained:<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cI am not stating nor implying that Propertyrec\u2019s customers or any individuals are at risk of impersonation, spear phishing, or social engineering attacks, I am only providing a real world risk scenario of how this type of information could possibly be exploited by criminals.\u201d<\/p>\n<\/blockquote>\n<p>And to make things worse\u2014if possible&#8211; the files had names that used the following format: \u201cFirst_Middle_Last_State.PDF.\u201d Which makes it incredibly easy for anyone, whether they are supposed to have access or not, to find a person of interest and read that file.<\/p>\n<p>It took the researcher quite a few calls and emails to get the exposed data taken out of public sight, and SL Data Services never provided the researcher with a response, let alone an explanation how this could happen.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-don-t-give-up-your-information-remove-it-where-you-can\">Don\u2019t give up your information, remove it where you can<\/h2>\n<p>Unfortunately, incidents like this are commonplace, so it\u2019s clear that we should take it upon ourselves to make sure our information can\u2019t be found by data brokers.<\/p>\n<p>Removing your personal information from data broker sites can be a complex and time-consuming process. While manual opt-outs are effective, they require considerable effort to keep up with new data entries and the reappearance of your information on various sites. This is where data broker removal services come in handy.&nbsp;<\/p>\n<p>Data broker removal services are designed to automate the process of finding and removing your personal information from data broker databases. These services regularly scan known databases for your information and submit opt-out requests on your behalf, ensuring a more comprehensive and continuous protection of your privacy.&nbsp;<\/p>\n<p>Malwarebytes offers a\u00a0<a href=\"https:\/\/www.malwarebytes.com\/personal-data-remover\">Personal Data Remover service<\/a>\u00a0(US only) that can delete your information from search results, spam lists, people search sites, data brokers, and more.<\/p>\n<div class=\"wp-block-malware-bytes-button mb-button\" id=\"mb-button-5330e905-aea6-4821-ae5e-f69c4eddf646\">\n<div class=\"mb-button__row u-justify-content-center\">\n<div class=\"mb-button__item mb-button-item-0\">\n<p class=\"btn-main\"><a href=\"https:\/\/www.malwarebytes.com\/personal-data-remover\">DELETE MY INFO<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/11\/data-broker-exposes-600000-sensitive-files-including-background-checks\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> A researcher has discovered a data broker had stored 644,869 PDF files in a publicly accessible cloud storage container. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[21397,32,5897,32184,32185],"class_list":["post-25507","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-data-broker","tag-news","tag-privacy","tag-propertyrec","tag-sl-data-services"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25507","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=25507"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25507\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=25507"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=25507"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=25507"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}