Personal data 198 million US voters were laid out in open access on the Amazon S3 server. The server is used by the analytical firm-contractor of the Republican Party, which collected these data during the presidential elections. The company assures that this was done to determine the best air time for political advertising.
The largest leak in history.
The personal data of more than 198 million American voters were inadvertently posted on the Internet. They were found on the server Amazon S3, occupied by the analytical company Deep Root Analytics (DRA), which collects information for the National Committee of the Republican Party of the United States. The data were not protected in any way and were in public access, they could be downloaded free of charge.
UpGuard called the incident the biggest incident of its kind, since 198 million are almost all registered voters of the United States, of which a total of about 200 million. The leak was discovered by UpGuard analyst on cyber-risks Chris Vickery (Chris Vickery), he also checked the authenticity of the data.
What kind of data flowed away.
The total leakage is about 1.1 TB. The data was collected by the DRA and two other Republican party contractors: analytical firms TargetPoint Consulting, Inc.. And Data Trust. The database contains information about the name, date of birth, home address, phone numbers, party affiliation of each voter and details of his registration. In addition, it indicates the likely ethnic and religious affiliation of citizens, as well as their alleged political beliefs, modeled by analysts of contracting companies.
The leaked base consists of dozens of tables. The information was collected in preparation for the presidential elections of 2016. , After which the US president was Donald Trump (Donald Trump), as well as during past election campaigns. The last time the data was updated in January 2017. , Approximately during the inauguration of the new president. For each voter in the database, the identification number assigned to him by the Republican Party during the presidential elections of 2008. And 2012 г. In the table, which is devoted to the election of 2016 g. , Not all voters are represented, but only residents of Ohio and Florida, who play a key role in the American elections.
Company Response.
Alex Lundry, co-founder of DRA, said that the company does occupy this Amazon S3 server, and also confirmed the leakage. The company is ready to assume "full responsibility for the situation". The IT department of DRA has already updated the access settings on the server and installed a protocol that will help avoid similar incidents. The investigation of the incident continues, however, according to preliminary data, this is not a hacker attack.
DRA reports that the data it collected was used to help politicians choose the best time to display their commercials on television. The data of the TargetPoint company found on the same server should simply give presidential candidates an idea of ??the political sympathies of the voters.
Similar incidents.
At the end of 2015. The same Chris Vickery reported another leak of US voters. The database, which numbered 191 million US citizens, contained their full names and addresses, birth dates, phone numbers, e-mail addresses, political preferences, ID, the voting history from 2000. , As well as the forecast of voters' voting in the upcoming elections.
Experts blamed the leak for the company NationBuilder, developing software for the conduct of elections. When Vickery and his colleagues failed to contact the representatives of this company, they reported an issue to the FBI, the California Attorney General's Office and the Internet Crime Complaint Center (IC3).
Later, NationBuilder stated that the IP on which the database was published does not belong to her or her clients, but experts expressed doubts about the sincerity of this statement, because, in their opinion, the database structure and its individual fields directly indicate membership in the database NationBuilder.
In April 2016 year. Vickery discovered another leak of this kind - this time it was about 87 million Mexican voters. The data composition was almost the same as in the US incidents: names, addresses, and t. Information was also found on the Amazon server. A little earlier in the same year 2016. Such a plum was admitted in the Philippines, it affected 70 million voters.