Learner driver data exposed in worrying breach - thousands affected

Trending 3 weeks ago
Data leak
(Image credit: Shutterstock)

A awesome Brazilian driving schoolhouse appears to person exposed nan delicate accusation of up to 400,000 individuals aft failing to decently unafraid a cloud database.

Researchers from Cybernews declare to person recovered an unprotected Google Cloud Storage bucket containing accusation astir Brazilian Learner’s Driving permits - Licença De Aprendizagem De Direção Veicular.

The learner licence is simply a archive that nan Brazilian authorities issues to group presently attending driving lessons, allowing them to thrust a conveyance during lessons. Cybernews says nan archive is astir apt owned by a driving schoolhouse from Sao Paulo, called Centro de Formação de Condutores Free Alda.

Still available

Most of nan exposed information carries a Detran insignia - which stands for State Department of Traffic (Departamento Estadual de Trânsito).

The researchers judge that up to 400,000 individuals person had delicate information exposed this way, including afloat names, photographs, postal addresses, authorities ID numbers, taxpayers’ numbers, specifications astir nan driving permit, including rumor day and validity period, signatures, IP addresses, and personification telephone models. This is much than capable to tally each sorts of cybercrime, from identity theft to ligament fraud.

The pros deliberation nan archive was either misconfigured, aliases not decently secured. It is intolerable to find for really agelong it remained open, aliases if anyone accessed it earlier they recovered it. The Cybernews squad says they made nan find connected June 2, and that nan schoolhouse was subsequently contacted by Brazil’s CERT. However, arsenic precocious arsenic September 19, nan archive was still unfastened to anyone who knew wherever to look.

“The exposed information could beryllium exploited by malicious actors for personality theft, fraud, aliases different forbidden activities. Moreover, a breach of this type tin undermine nationalist spot successful governmental agencies responsible for managing and protecting delicate individual information,” Cybernews researchers said.

Sign up to nan TechRadar Pro newsletter to get each nan apical news, opinion, features and guidance your business needs to succeed!

More from TechRadar Pro

  • Mystery database containing delicate info connected 762,000 car-owners discovered by researchers
  • Here's a database of nan best firewalls today
  • These are nan best endpoint protection tools correct now

Sead is simply a seasoned freelance journalist based successful Sarajevo, Bosnia and Herzegovina. He writes astir IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, information breaches, laws and regulations). In his career, spanning much than a decade, he’s written for galore media outlets, including Al Jazeera Balkans. He’s besides held respective modules connected contented penning for Represent Communications.

More
Source Technology
Technology