Two million Dow Jones customer details exposed via cloud

Personal details and some credit card info were vulnerable to hackers

At least two million Dow Jones customers have had personal details exposed online via an unsecured cloud file repository.

Dow Jones, which owns the Wall Street Journal, confirmed to IT Pro that approximately 2.2 million customers were affected, though cybersecurity firm UpGuard estimates the number to be closer to four million accounts.

80% of respondents to the Cyber Risk Appetite Survey have experienced at least one serious security incident in the last year. Download the whitepaper for more research:

Download now

The exposed information included the names, addresses, account information, email addresses, and last four digits of credit card numbers.

There were also 1.6 million exposed entries in a collection of databases known as "Dow Jones Risk and Compliance", which are subscription-based programmes used by financial institutions to understand how to be compliant with anti-money laundering regulations.

The data was found on an Amazon Web Services (AWS) S3 bucket, and had been configured to allow any AWS "Authenticated Users" to download the data. Amazon defines an authenticated user as any person with an AWS account, of which there are over a million users, and is free to sign up to.

A spokesperson for Dow Jones told IT Pro: "We were made aware that certain Dow Jones/WSJ subscriber and Risk & Compliance content was over-exposed on Amazon Cloud (not the open internet). This was due to an internal error, not a hack or attack. The customer information included basic contact information; it did not include full credit card or account login information that could pose a significant risk for consumers or require notification."

The spokesperson added: "The Risk & Compliance data included content curated exclusively from publicly available sources such as newspaper articles, government issued watch lists, and other publicly available information; it did not include any customer information. We have no evidence any of the [exposed] information was taken. Even so, we immediately secured the data once we became aware of the problem. We take the security of Dow Jones information very seriously."

Dan O'Sullivan, cyber resilience analyst at UpGuard, stated that the unsecured information "would be of use to any spammers or digital marketers, but could also be used [for a] far more malign effect". Malicious actors, for instance, could use the information for phishing, pretending to be from the Wall Street Journal and telling customers their account had been compromised or that there was a problem with their subscription.

Dow Jones isn't the only company to have exposed customer details online via an AWS server - a Verizon data breach last week saw six million customer records compromised on an unprotected AWS S3 storage server. Each record included the customer's name, mobile number, and account PIN as well as their home and email address, and Verizon account balance.

Verizon stated that there was no loss or theft of Verizon customer information and that "the overwhelmingly majority of information in the data set had no external value, although there was a limited amount of personal information included".

Meanwhile, the WWE exposed three million fans' accounts online in the same manner, and the AA also suffered a similar fate.

RSA's Cyber Risk Appetite Survey uses research from 272 risk and security professionals across the globe. Download it for free here.

Download now

Featured Resources

Security analytics for your multi-cloud deployments

IBM Security QRadar SIEM solution brief

Download now

Five reasons to move to the cloud

Join the enterprises moving their workloads to the cloud

Download now

Architecting hybrid IT and edge for digital advantage

Why business leaders should consider a hybrid IT strategy

Download now

Six reasons to accelerate remote asset monitoring with AI

How to optimise resources, increase productivity, and grow profit margins with AI

Download now

Recommended

Cyber security firm saw attacks rise by 20% during 2020
cyber security

Cyber security firm saw attacks rise by 20% during 2020

23 Feb 2021
What to look for in a secure cloud system
cloud security

What to look for in a secure cloud system

23 Feb 2021
Hackers turn to 'silent stealing' in bid to exploit home workers
scams

Hackers turn to 'silent stealing' in bid to exploit home workers

22 Feb 2021
Kia Motors allegedly suffers a ransomware attack
data breaches

Kia Motors allegedly suffers a ransomware attack

18 Feb 2021

Most Popular

Mysterious Silver Sparrow malware hits 30,000 macOS devices
malware

Mysterious Silver Sparrow malware hits 30,000 macOS devices

22 Feb 2021
IBM reportedly mulls sale of Watson Health business
mergers and acquisitions

IBM reportedly mulls sale of Watson Health business

22 Feb 2021
Microsoft to launch standalone Office 2021 suite
Microsoft Office

Microsoft to launch standalone Office 2021 suite

19 Feb 2021