【Friend’s Mothers 4】

【Friend’s Mothers 4】

An unsecured FedEx server was breached,Friend’s Mothers 4 exposing thousands of customers' personal information, a prominent security research firm discovered earlier this month.

Package forwarding service Bongo International was acquired by FedEx in 2014 and now serves as a e-commerce service called FedEx Cross Border.

But an unsecured Amazon S3 server, according to the white hat research group Kromtech, was holding more than 100,000 scanned documents including passports, drivers licenses, and security IDs. The white hat group responsibly disclosed the breach.

SEE ALSO: Olympic organizers hit with hack during opening ceremony

In a statement a FedEx spokesperson said the server has since been secured, and the data wasn't "misappropriated." The full statement reads:

Mashable Light Speed Want more out-of-this world tech, space and science stories? Sign up for Mashable's weekly Light Speed newsletter. By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy. Thanks for signing up!

After a preliminary investigation, we can confirm that some archived Bongo International account information located on a server hosted by a third-party, public cloud provider is secure. The data was part of a service that was discontinued after our acquisition of Bongo.  We have found no indication that any information has been misappropriated and will continue our investigation.

Kromtech was able to get in touch with FedEx through a reporter earlier this week and secure the compromised data. This likely means anyone whose information was housed in that server is safe.

Alex Heid, white hat hacker and chief research officer at SecurityScorecard, said in a call it's very likely none of the data was used, but it was sitting there for a long time. "Thankfully this group was working to report that type of stuff," unlike the Equifax breach last year where the information was used maliciously.

He said this type of information leak is "incredibly common" as "new big data technologies become easier to use," but companies don't necessarily know how to use and secure them, like this Amazon S3 server forgotten in an years-old acquisition.

He said FedEx shouldn't be judged for having the data open, but on how they react to the exposure. "It’s a matter of having a program in place when it happens," Heid said.


Featured Video For You
AI will become the criminal hacker's best friend—and worst enemy

Topics Cybersecurity

Comments

Leave a Comment