Unprotected Server Exposes 24 Million Sensitive Banking Documents

A major security lapse leaves tens of thousands of US banking and mortgage documents openly accessible on the internet. The leak traces back to a contractor working for financial data firm Ascension.

A security researcher discovers a massive cache of over 24 million financial and banking documents exposed on the internet due to a server security lapse. The unprotected Elasticsearch database contains more than a decade's worth of sensitive data, including loan agreements, repayment schedules, and tax documents from major U.S. banks. Because the server lacks password protection, anyone can access and read the highly personal financial information during the two-week exposure window.

Following an inquiry from TechCrunch, the exposed database traces back to Ascension, a Texas-based data and analytics company serving the financial industry. Ascension relies on a New York-based contractor called OpticsML to convert paper documents into computer-readable files through optical character recognition. It is this specific repository of digitized documents that remains completely unsecured and open to the public.

Ascension's parent company, Rocktop Partners, confirms the security incident and states that the vendor immediately shuts down the affected server upon discovering the configuration error. The company now works with third-party forensics experts and law enforcement to investigate the scope of the breach. Meanwhile, OpticsML goes completely offline, its website disappears, and its phone number disconnects just as a second storage server containing the original documents surfaces.

Read More at the original source →