A hotel check-in platform left its cloud storage publicly accessible, exposing approximately one million customer passports and driver's licenses without password protection.
The tech company operating the system misconfigured its cloud storage settings, setting the database to public instead of restricting access to authorized personnel only. Anyone with an internet connection could view the sensitive identification documents.
The exposed data included full copies of passports and driver's licenses from hotel guests across multiple properties. No authentication was required to access the information.
The misconfiguration was discovered and reported to the company, which secured the storage following notification. The exact number of affected individuals and the duration the data remained exposed have not been fully disclosed.
This incident highlights a recurring vulnerability in hospitality technology: the storage of high-value personal identification data combined with inadequate security controls. Hotels collect ID documents during check-in to verify guest identity and comply with regulations, but improper storage creates significant privacy risks.
Cloud storage misconfigurations remain a leading cause of data breaches across industries. Security best practices require that sensitive data be stored with encryption, access controls, and authentication requirements. Default settings should assume private storage unless explicitly configured otherwise.
The incident raises questions about the company's security protocols and oversight mechanisms. Organizations handling sensitive customer data face increasing scrutiny from regulators and the public following high-profile breaches.
Affected guests may face elevated identity theft risks. Passports and driver's licenses provide sufficient information for fraudsters to commit identity fraud or create forged documents.
Fraudsters are exploiting Microsoft Teams and similar enterprise chat apps to deceive Chinese users into sending large sums of money. The trend has sparked a wave of complaints across the region.
The Bureau of Alcohol, Tobacco, Firearms and Explosives has notified Congress of a major cybersecurity incident after a ransomware gang claimed responsibility for breaching the agency's systems.
Google is rolling out Encrypted Client Hello (ECH) support in Android 17 to prevent network monitoring of user browsing activity. The privacy feature strengthens connection security across cellular and home networks.
A new survey shows more Americans oppose police use of license plate readers than support them. The finding reflects growing concerns about surveillance overreach.