Data on every Ecuadorian citizen leaked online

Information relating to almost 17 million people left exposed on an AWS server

Ecuador flag

The personal data of almost every Ecuadorian citizen has been exposed online, according to a report.

Details such as names, address and financial information of about 17 million people were found publicly exposed on an AWS server by security company vpnMentor, which made the discovery during a large-scale mapping project.

An Ecuadorian government-led security team has now managed to restrict access to the server, but the information might already be in the hands of hackers.

"The data breach involves a large amount of sensitive personally identifiable information at the individual level," wrote Noam Rotem and Ran Locar, from vpnMentor. The majority of the affected individuals seem to be located in Ecuador.

Advertisement
Advertisement - Article continues below

"Although the exact details remain unclear, the leaked database appears to contain information obtained from outside sources. These sources may include Ecuadorian government registries, an automotive association called Aeade, and Biess, an Ecuadorian national bank."

The cache contained around 18 GB of data, with as many as 20 million individuals potentially affected. For context, the population of Ecuador is around 16 million.

Ecuadorian individuals in the database were identified by a ten-digit national identification code, similar to a social security number used in the US, which also included their unique taxpayer registry.

vpnMentor used a random one of these ID numbers to run a search and were able to find a variety of sensitive personal information. The team were able to identify the name, gender, date and place of birth, home and email address, work details, marriage information and even education of an individual. The report notes that some of the data involved individuals who may be deceased, but this also included bank account details.

What's more, the data also opened up insights into a person's family, with each entry linking to relatives and even spouses.

vpnMentor said this kind of data breach could have been prevented with basic security measures, such as implementing an appropriate access rule, but it also suggested it might be too late to prevent hacks.

"Once data has been exposed to the world, it can't be undone," the team wrote. "The database is now closed, but the information may already be in the hands of malicious parties."

vpnMentor has helped uncover a string of high-profile data breaches over the past month, including a hack on adult content-sharing site Luscious, which involved 1 million users, and the potential leak of a massive biometric data set owned by Suprema and used by the likes of the Met police and major banking groups.

Featured Resources

The IT Pro guide to Windows 10 migration

Everything you need to know for a successful transition

Download now

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Software-defined storage for dummies

Control storage costs, eliminate storage bottlenecks and solve storage management challenges

Download now

6 best practices for escaping ransomware

A complete guide to tackling ransomware attacks

Download now
Advertisement

Most Popular

Visit/security/identity-and-access-management-iam/354289/44-million-microsoft-customers-found-using
identity and access management (IAM)

44 million Microsoft customers found using compromised passwords

6 Dec 2019
Visit/cloud/microsoft-azure/354230/microsoft-not-amazon-is-going-to-win-the-cloud-wars
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
Visit/hardware/354237/five-signs-that-its-time-to-retire-it-kit
Sponsored

Five signs that it’s time to retire IT kit

29 Nov 2019
Visit/mobile/5g/354286/why-5g-could-be-a-cyber-security-nightmare
5G

Why 5G could be a cyber security nightmare

6 Dec 2019