An unsecured FedEx server was breached,Watch Officetel: Lover Friend Online exposing thousands of customers' personal information, a prominent security research firm discovered earlier this month.
Package forwarding service Bongo International was acquired by FedEx in 2014 and now serves as a e-commerce service called FedEx Cross Border.
But an unsecured Amazon S3 server, according to the white hat research group Kromtech, was holding more than 100,000 scanned documents including passports, drivers licenses, and security IDs. The white hat group responsibly disclosed the breach.
SEE ALSO: Olympic organizers hit with hack during opening ceremonyIn a statement a FedEx spokesperson said the server has since been secured, and the data wasn't "misappropriated." The full statement reads:
After a preliminary investigation, we can confirm that some archived Bongo International account information located on a server hosted by a third-party, public cloud provider is secure. The data was part of a service that was discontinued after our acquisition of Bongo. We have found no indication that any information has been misappropriated and will continue our investigation.
Kromtech was able to get in touch with FedEx through a reporter earlier this week and secure the compromised data. This likely means anyone whose information was housed in that server is safe.
Alex Heid, white hat hacker and chief research officer at SecurityScorecard, said in a call it's very likely none of the data was used, but it was sitting there for a long time. "Thankfully this group was working to report that type of stuff," unlike the Equifax breach last year where the information was used maliciously.
He said this type of information leak is "incredibly common" as "new big data technologies become easier to use," but companies don't necessarily know how to use and secure them, like this Amazon S3 server forgotten in an years-old acquisition.
He said FedEx shouldn't be judged for having the data open, but on how they react to the exposure. "It’s a matter of having a program in place when it happens," Heid said.
Topics Cybersecurity
(Editor: {typename type="name"/})
The New York Post's push alerts just got real dark
Your internet privacy is gone and more sad news in podcast form
Trump’s Family Leave Shell Game
I made an exact replica of Donald Trump in 'The Sims 3' and a lot of wild things happened
Vin Diesel laser cut out of ham and cheese is a sandwich masterpiece
Hey Crayola, quit dragging on this elaborate crayon saga. We've had enough.
What happened to our 'Grimm' favorites after the series finale?
Bafflersplainer: Win the Future
A square that's home to 11 statues of men and no statues of women is about to get a big change
接受PR>=1、BR>=1,流量相当,内容相关类链接。