Data broker leaves 600K+ sensitive files exposed online

Share:

Exclusive More than 600,000 sensitive files containing thousands of people’s criminal histories, background checks, vehicle and property records were exposed to the internet in a non-password protected database belonging to data brokerage SL Data Services, according to a security researcher.

We don’t know how long the personal information was openly accessible. Infosec specialist Jeremiah Fowler says he found the Amazon S3 bucket in October and reported it to the data collection company by phone and email every few days for more than two weeks.

In addition to not being password protected, none of the information was encrypted, he told The Register. In total, the open bucket contained 644,869 PDF files in a 713.1 GB archive.

“Even when I would make phone calls to the multiple numbers on different websites and tell them there was a data incident, they would tell me they use 128-bit encryption and use SSL certificates – there were many eye rolls,” he claimed.

Some 95 percent of the documents Fowler saw were labeled “background checks,” he said. These contained full names, home addresses, phone numbers, email addresses, employment, family members, social media accounts, and criminal record history belonging to thousands of people. In at least one of these documents, the criminal record indicated that the person had been convicted of sexual misconduct. It included case details, fines, dates, and additional charges.

While court records and sex offender status are usually public records in the US, this exposed cache could be combined with other data points to make complete profiles of people – along with their family members and co-workers – providing everything criminals would need for targeted phishing and/or social engineering attacks.

“The biggest risk in my opinion would be the way they compile a full picture and profile of an individual that is far beyond just the basic semi-public information that could be out there online,” Fowler told The Register. “This puts both the individual and their family or associates at potential risk – or even individuals who have nothing to do with the person identified in the background check.”

Criminals could also potentially use this exposed info to obtain other sensitive personal or financial details, he added.

“As you know when it comes to phishing, the more information you have about a person, the better,” Fowler noted. “Knowing things like employment, criminal records, and family members from one report raises a lot of security concerns.”

The info service provider eventually closed up the S3 bucket, says Fowler, although he never received any response. The Register also reached out to SL Data Services for comment and did not hear back.

While there’s no indication that criminals spotted the open database and snooped through the sensitive files therein, we’ve seen plenty of recent examples of the nefarious purposes that this type of personal information could be used for if it fell into the wrong hands.

Earlier this year, digital thieves ransacked another background check firm and then later listed – for $3.5 million on a cybercrime forum – what the crooks claimed to be 2.9 billion sensitive records linked to US, Canadian, and British citizens.

  • National Public Data files for bankruptcy, admits ‘hundreds of millions’ potentially affected
  • After nearly 3B personal records leak online, Florida data broker confirms it was ransacked by cyber-thieves
  • Fore-get about privacy, golf tech biz leaves 32M data records on the fairway
  • 31.5M invoices, contracts, patient consent forms, and more exposed to the internet

In August, National Public Data confirmed the intrusion and massive data leak. Last month, its parent company, Jericho Pictures, filed for bankruptcy, admitting “hundreds of millions” of people were potentially affected.

SL Data Services claims to provide property reports – including property and lien data, owner and neighbor information, crime and school info, plus mortgage and tax data – for residential real estate across the US, according to its Better Business Bureau profile.

While the open database that Fowler says he found belonged to SL Data Services, the folders inside were named with separate website domains, he observed, adding that the firm appears to operate at least 16 different websites that provide a range of different data. “For instance, PropertyRec, a website that advertises property and real estate research data, was mentioned in the database’s name,” Fowler wrote in a report slated to be published on Wednesday.

Match made in heaven: property records + criminal checks

“However, it seems the company offers more than just property records,” he added. “In a phone call to customer support, I was told they also provide criminal checks, division of motor vehicles (DMV) records, death and birth records.”

PropertyRec did not respond to The Register‘s request for comment.

Another troubling aspect is that the files in the database were named using this format: “First_Middle_Last_State.PDF.”

While this naming mechanism provides an easy way to organize and search files, Fowler also recommends that organizations use unique identifiers that are random and hashed, and otherwise don’t include any personal or identifiable information.

He suggests any organization that collects and stores sensitive data monitors its access logs. “This can help identify any unusual patterns – such as instances of mass viewing or downloading of files from the organization’s cloud storage database or internal network,” Fowler explained.

Jessica Lyons

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:26 am, Jul 11, 2025
weather icon 18°C
L: 17° | H: 19°
broken clouds
Humidity: 79 %
Pressure: 1021 mb
Wind: 7 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 60%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:56 am
Sunset: 9:15 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
17° | 19°°C 0 mm 0% 8 mph 79 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 10 mph 66 % 1019 mb 0 mm/h
Sun Jul 13 10:00 pm
weather icon
18° | 30°°C 0 mm 0% 7 mph 71 % 1015 mb 0 mm/h
Mon Jul 14 10:00 pm
weather icon
18° | 28°°C 1 mm 100% 15 mph 84 % 1016 mb 0 mm/h
Tue Jul 15 10:00 pm
weather icon
14° | 20°°C 1 mm 100% 14 mph 81 % 1017 mb 0 mm/h
Today 4:00 am
weather icon
17° | 18°°C 0 mm 0% 3 mph 79 % 1021 mb 0 mm/h
Today 7:00 am
weather icon
18° | 19°°C 0 mm 0% 2 mph 75 % 1021 mb 0 mm/h
Today 10:00 am
weather icon
24° | 27°°C 0 mm 0% 2 mph 57 % 1021 mb 0 mm/h
Today 1:00 pm
weather icon
30° | 30°°C 0 mm 0% 3 mph 32 % 1020 mb 0 mm/h
Today 4:00 pm
weather icon
32° | 32°°C 0 mm 0% 4 mph 26 % 1018 mb 0 mm/h
Today 7:00 pm
weather icon
30° | 30°°C 0 mm 0% 6 mph 29 % 1017 mb 0 mm/h
Today 10:00 pm
weather icon
23° | 23°°C 0 mm 0% 8 mph 49 % 1019 mb 0 mm/h
Tomorrow 1:00 am
weather icon
21° | 21°°C 0 mm 0% 5 mph 57 % 1019 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€99,245.34
4.20%
Ethereum(ETH)
€2,529.28
6.20%
Tether(USDT)
€0.85
-0.02%
XRP(XRP)
€2.20
5.67%
Solana(SOL)
€140.46
3.54%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.167882
8.49%
Shiba Inu(SHIB)
€0.000012
9.22%
Pepe(PEPE)
€0.000010
13.30%
Peanut the Squirrel(PNUT)
€0.245548
22.13%
Scroll to Top