Hundreds of thousands of voter records exposed on misconfigured server, researcher says
Full article541 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Another S3 bucket exposing voter data.
Yet another misconfigured Amazon S3 bucket has exposed the sensitive information of unsuspecting people.
This time, hundreds of thousands of voters’ information was left open for the taking by a Virginia robocalling firm called RoboCent, according to Bob Diachenko, a security researcher at cybersecurity firm Kromtech.
Diachenko wrote in a LinkedIn blog post Wednesday that he discovered a trove of about 26,000 files, including audio files with pre-recorded political messages and spreadsheets containing voter information, in the leaky server.
The voter data, according to Diachenko, includes names, phone numbers, addresses, political affiliations, birth dates, genders, jurisdictions and some demographic information.
The RoboCent files were accessible to anyone who did a specialized web search for “voters,” said Diachenko.
By the time it was identified by Kromtech, the server had already been indexed by GrayhatWarfare, another website that scans the internet for open S3 buckets.
Diachenko says he disclosed the finding to RoboCent and a developer with the company who quickly secured the bucket. The data also appears to no longer be available on GrayhatWarfare.
According to its website, RoboCent offers a number of services to help organizations target voters, including voter turnout records as well as automated calling. One record goes for 3 cents.
Much of the voter data that was found exposed is already public information. State governments often make voter rolls available by request to journalists, researchers and political organizations. In some cases, they can be freely downloaded online.
The RoboCent case is the latest in a series of incidents that shows how a simple server misconfiguration can leave voters’ personal information open for anyone.
A set of 191 million voter records was found exposed in 2015 and another set of 198 million records was discovered last year. Also, the American Civil Liberties Union is suing the Kansas secretary of state for allegedly exposing voter data, including partial Social Security Numbers, used in a program aiming to detect voter fraud.
ZDNet first reported the discovery by Kromtech.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/robocent-voter-records-exposed/