Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

Security Firm: Data Breach Exposes Millions of Ecuadorians

Millions of Ecuadorians are at risk of identity theft because a security breach exposed a trove of data including names, phone numbers and birth dates, a cyber security firm said Monday.

Millions of Ecuadorians are at risk of identity theft because a security breach exposed a trove of data including names, phone numbers and birth dates, a cyber security firm said Monday.

Researchers at vpnMentor said the problem stemmed from an unsecured server located in Miami that contained information on over 20 million individuals, most of whom reside in Ecuador. The small South American nation is home to just over 17 million people, meaning nearly everyone could have been exposed.

Ecuadorian President Lenin Moreno said he would push through legislation to ensure stricter data security, while Interior Minister María Paula Romo vowed to hold those responsible accountable.

“The information we’ve received is very serious,” she said.

Experts said Ecuador does not have mechanisms in place requiring companies to protect personal data.

According to vpnMentor, the server in question is owned by Ecuadorian company Novaestrat, which did not respond to requests for comment from The Associated Press.

It wasn’t immediately clear if anyone had wrongfully accessed the data. And while vpnMentor said the breach was closed Wednesday, it also noted the impact can be long lasting.

The information could potentially be used to commit everything from phone scam to business fraud.

Advertisement. Scroll to continue reading.

“A malicious party with access to the leaked data could possibly gather enough information to gain access to bank accounts and more,” the firm said in a statement.

The data includes national identity card numbers, tax identification numbers and even names of relatives.

The researchers said WikiLeaks founder Julian Assange is among those in the database. The Ecuadorian government granted Assange citizenship during his nearly seven-year stay at the nation’s London embassy. According to the firm, researchers found his name and what is believed to be a national identity number.

The breach is one of several large-scale security lapses exposing the personal data of millions this year.

In July, Capital One said a hacker had accessed the personal information of 106 million credit card holders or credit card applicants in the United States and Canada.

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Artificial Intelligence

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Incident Response

Microsoft has rolled out a preview version of Security Copilot, a ChatGPT-powered tool to help organizations automate cybersecurity tasks.