BreachesHIGH

Duc App - Hundreds of Thousands of Personal Records Exposed

Featured image for Duc App - Hundreds of Thousands of Personal Records Exposed
SCSC Media
Duc Appdata exposurepersonal recordsserver misconfigurationDuales
🎯

Basically, Duc App accidentally made a lot of personal information public because of a mistake with their server settings.

Quick Summary

Duc App's server misconfiguration exposed sensitive personal records of users. This incident affects hundreds of thousands, raising serious privacy concerns. Users should monitor their information closely.

What Happened

Duc App, a money-transfer service owned by Duales, has suffered a significant data exposure incident. A publicly accessible Amazon-hosted storage server was left without password protection, allowing sensitive personal data of potentially hundreds of thousands of users to be exposed. This incident was reported by TechCrunch after security researcher Anurag Sen discovered the lapse.

Who's Affected

The exposed data includes unencrypted driver's licenses, passports, and other identity verification documents. Additionally, personal information such as names, home addresses, and selfies were also accessible. The data dates back to September 2020 and was uploaded daily, impacting a wide range of users who trusted Duc App with their sensitive information.

What Data Was Exposed

The nature of the exposed data is alarming. Users' driver's licenses and passports are critical identity documents that can lead to identity theft if misused. The presence of selfies and personal addresses further compounds the risk, making it easier for malicious actors to impersonate individuals or engage in fraud.

What You Should Do

If you are a user of Duc App, it is crucial to monitor your financial accounts and personal information for any signs of misuse. Consider changing passwords and enabling two-factor authentication on your accounts. Additionally, be vigilant about any unsolicited communications that may attempt to exploit this data exposure.

Duales has stated that the data was on a "staging site" and claimed to have resolved the exposure after being notified. However, a list of server contents remained visible, raising concerns about the effectiveness of their response and the overall security practices in place. This incident serves as a stark reminder of the importance of securing sensitive data and ensuring that servers are properly configured to prevent unauthorized access.

🔒 Pro insight: This incident underscores the critical need for robust server configurations to safeguard sensitive user data against exposure.

Original article from

SCSC Media
Read Full Article

Related Pings

HIGHBreaches

Texas Hospital Hack - Over 257K Patients Compromised

A major cyberattack on a Texas hospital has compromised the personal and medical data of over 257,000 patients. This breach raises serious privacy concerns, highlighting vulnerabilities in healthcare security. Immediate action is crucial to protect affected individuals from potential identity theft.

SC Media·
HIGHBreaches

European Commission Breach - Multiple EU Entities Affected

A major breach at the European Commission has compromised data from 29 EU entities. Personal information and email communications are at risk. Organizations must act swiftly to enhance their security measures.

SC Media·
HIGHBreaches

Meta Pauses Work With Mercor After Data Breach Incident

Meta has paused its collaboration with Mercor due to a data breach. This incident could expose sensitive AI training data, impacting major AI labs. Investigations are ongoing to assess the breach's implications.

Wired Security·
HIGHBreaches

Internet-Connected Coffee Machine Leads to Major Data Breach

A coffee machine connected to the internet caused a major data breach by exploiting weak security. This incident reveals the vulnerabilities of IoT devices and the risks they pose to businesses. Organizations must strengthen their security measures to protect sensitive data.

SC Media·
HIGHBreaches

EU Cyber Agency Attributes Major Data Breach to TeamPCP

A major data breach at the European Commission has been linked to the TeamPCP hacking group. Sensitive data from various EU entities has been exposed, raising serious privacy concerns. Cybersecurity officials are investigating the incident and urging better security practices.

The Record·
HIGHBreaches

Hims & Hers - Data Breach Exposes Support Ticket Information

Hims & Hers has reported a data breach affecting support tickets on Zendesk. Personal information may have been compromised, prompting the company to offer free credit monitoring. Customers are advised to stay vigilant against phishing attempts.

BleepingComputer·