Cybernews reports that Iranian cryptocurrency exchange Bit24.cash had almost 230,000 of its users' sensitive information accidentally compromised after S3 buckets storing its Know Your Customer verification data became accessible due to a misconfiguration in its MinIO object storage system.
Information leaked by the misconfiguration included individuals' IDs, credit cards, and passports, as well as their written consent to KYC laws. While Bit24.cash has since secured the misconfigured cloud storage system, the severity of such exposure has been emphasized by Cybernews researchers.
"This breach poses a severe threat, as threat actors could potentially exploit the exposed data for identity theft, fraudulent transactions, and phishing attacks. With access to such comprehensive personal and financial data, malicious actors could impersonate individuals, gain unauthorized access to accounts, execute fraudulent transactions, and potentially cause substantial financial and personal harm to the affected users," said researchers.
Cloud Security, Data Security, Privacy
Almost 230K hit by Bit24.cash data leak
An In-Depth Guide to Cloud Security
Get essential knowledge and practical strategies to fortify your cloud security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds