Friday, November 1, 2024
HomeData BreachVerizon Partner Exposed Around 14 Million's of Customer Accounts Sensitive Data Online

Verizon Partner Exposed Around 14 Million’s of Customer Accounts Sensitive Data Online

Published on

Malware protection

Verizon owned as many as 14 Millions of customer’s data exposed online by telephonic software and data firm NICE Systems, a third-party vendor for Verizon due to a misconfiguration in their cloud server.

Recent days many companies are continually suffering massive Data breaches, and cyber threats and attacks are increasing day by day around the world.

Verizon customers personal information has managed in Amazons Web Services S3 bucket that is administrated by NICE Systems engineers.

- Advertisement - SIEM as a Service

Verizon using NICE Systems technology in its back-office and call center operations and other related technical operations.

The exposed sensitive information contains customer names, addresses, account details, and account personal identification numbers (PINs) of as many as 14 million US customers.

Apart from this leak, also Exposed Verizon account PIN codes used to verify customers, listed alongside their associated phone numbers.

A Discovered Amazon cloud S3 bucket repository was fully downloadable and configured to allow public access which contains many terabytes of contents could thus be accessed merely by entering the S3 URL.

Accoring to UpGuard report,The repository’s subdomain, “verizon-sftp,” is an indication of the files’ corporate origins. Viewing the repository, there are six folders titled “Jan-2017” through “June-2017,” as well as a number of files formatted with .zip, among them “VoiceSessionFiltered.zip” and “WebMobileContainment.zip.” These files, inaccessible via .zip extraction, could be decompressed once the format was changed to .gzip, another file compression program.

In this discovered folders that show the date that contains each month of data, each of these day folders is a couple dozen or so compressed files which is capable of the store the daily records automatically in respective folders.

After unzipped the files, it revealed a larger amount of text files that contains almost 23GB of data where the folder have composed of voice recognition log files, the records of an individual’s call to a customer support line, including fields like “TimeInQueue” and “TransferToAgent.” Pings to various subdomains of https://voiceportalfh.verizon.com further indicate the voice-activated technology producing this data.

Apart from this many exposed Verizon account contains logs, such as customer names, addresses, and phone numbers, as well as information fields indicating customer satisfaction tracking, such as “frustration level,.”

Exposed data are very sensitive information such as a PIN, CUSTCODE are masked for some of customers data, but not all the accounts confidential information are masked, some of the accounts revealing such details as unmasked “PIN” codes.

“The critical data repository in question was exposed not by the enterprise holding primary responsibility for the information, but by a third-party vendor to the enterprise. It was a publicly accessible AWS S3 bucket owned by third-party vendor NICE Systems that revealed the sensitive personal details of Verizon customers”. UpGaurd said.

Some of Very Recent Data Leaked Online

  1. Famous Cosmetic Company “Tarte” leaked 2 Million Customers Personal Data Online
  2. Fashion Retailer FOREVER 21 Admits Payment Card Security Breach
  3. Accenture Data Leak Exposed 137 Gigabytes of Highly Sensitive Data Online
  4.  Deloitte Hacked by Cyber Criminals and Revealed Client & Employee’s Secret Emails
  5. Leading research and advisory firms Forrester was hacked
  6. Disqus confirms it’s been hacked and more than 17.5 Million Users Details Exposed
  7. Gaming Service R6DB Database deleted By Hackers and held for Ransom
  8. Biggest Hack Ever – Each and Every Single Yahoo Account Was Hacked in 2013
  9. Pizza Hut Hacked – Users Reporting Fraudulent Transactions on their Cards
  10. Hyatt Hotels Data Breach Exposed 41 Hotel Customers Payment Card Information
  11. Verizon Wireless Confidential DataLeaked Accidentally by Its Employee
  12. ABC Company Massive Data Leaked online from Amazon S3 Bucket
  13. Pentagon Data Leak Exposed 1.8 Billion of Social Media Surveillance Data
  14. Uber Data Breach Exposed Personal Information of 57 Million Uber Users
  15. HP Exposed more than 400,000 Customers Sensitive Information Online
  16. Imgur Data Breach Exposed 1.7 Million Users Emails and Passwords by Hackers
  17. Paypal Acquired firm TIO Networks Data Breach that Impacts 1.6 Million Customers

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

LightSpy iOS Malware Enhanced with 28 New Destructive Plugins

The LightSpy threat actor exploited publicly available vulnerabilities and jailbreak kits to compromise iOS...

ATPC Cyber Forum to Focus on Next Generation Cybersecurity and Artificial Intelligence Issues

White House National Cyber Director, CEOs, Key Financial Services Companies, Congressional and Executive Branch...

New PySilon RAT Abusing Discord Platform to Maintain Persistence

Cybersecurity experts have identified a new Remote Access Trojan (RAT) named PySilon. This Trojan...

Konni APT Hackers Attacking Organizations with New Spear-Phishing Tactics

The notorious Konni Advanced Persistent Threat (APT) group has intensified its cyber assault on...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Grayscale Investments Data Breach Exposes 693K User Records Reportedly Affected

Grayscale Investments, a prominent crypto asset manager, has reportedly suffered a data breach affecting...

Northern Ireland Police to Pay £750,000 Fine Following Data Breach

The Police Service of Northern Ireland (PSNI) has been ordered to pay a £750,000...

Google Warns Of North Korean IT Workers Have Infiltrated The U.S. Workforce

North Korean IT workers, disguised as non-North Koreans, infiltrate various industries to generate revenue...