Exposed U.S. voter database poses 'extreme' danger, researcher says
Full article645 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The database contained personal data on more than 150 million people — including voters’ addresses, full names and political stances.
Millions of voters are now at risk for ‘countless scams’ after their records were exposed by an improperly secured database, said Chris Vickery, a white hat cybersecurity researcher who uncovered the vulnerability.
“The dangers are extreme,” Vickery told FedScoop in an email.
He added, ‘Imagine the havoc that could be caused by phone scammers knowing the age and cell phone number of every voter in America. That’s a large group of elderly, naive targets to reap. Also, think how much a spammer would value a nearly up-to-date list of millions and millions of voter email addresses. That’s not to mention the potential harm coming from a list of every voters’ ethnicity.’
Last week, Vickery announced in a blog post that he discovered an exposed ‘database containing profiles for 154 million American voters.’ The database, which is owned by Seattle-based nonpartisan political data brokerage firm L2 and was sold to an undisclosed customer, held voters’ home addresses, full names, political preferences and their opinions concerning issues like gun control and same-sex marriage.
Vickery, who works at security software firm MacKeeper, said a database misconfiguration was likely to blame. The unnamed L2 client had previously claimed their account was hacked.
[Read More: Database leak exposes 191M voter registration records]
While it remains unclear whether an unauthorized user captured data before the vulnerability was patched, a log file showed that while the database was left open, it was accessed from a Serbian IP address, Vickery said. At the same time, he noted that authorized users could choose to mask their IP for an added layer of security.
L2 CEO Bruce Willsie said in a statement shortly after the vulnerability was disclosed that his company took immediate action.
“We very quickly identified the national client, informed them immediately and they took down the site as quickly as they could.’
FedScoop reached out to L2 for comment but did not receive a response before publication. Though, L2 told The Hill that the exposed voter information was roughly a year old.
Vickery told FedScoop that if the database were leaked online, it should concern American gun owners, who would be “alarmed to learn that they really are being tracked.”
“Little bits of info here and there may be innocuous, but when you concentrate some of the most sensitive aspects of millions of peoples’ lives, it becomes potent and destructive in the wrong hands,’ Vickery said. ‘The number of scams you could pull off with such a database is only limited by your imagination.’
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/exposed-u-s-voter-database-poses-extreme-danger-researcher-says-2/