{"id":393697,"date":"2019-01-22T07:51:02","date_gmt":"2019-01-22T06:51:02","guid":{"rendered":"http:\/\/rinf.com\/alt-news\/newswire\/7-years-of-fbi-data-corporate-info-ssns-names-of-aids-patients-exposed-rt-usa-news\/"},"modified":"2019-01-22T07:51:02","modified_gmt":"2019-01-22T06:51:02","slug":"7-years-of-fbi-data-corporate-info-ssns-names-of-aids-patients-exposed-rt-usa-news","status":"publish","type":"post","link":"http:\/\/rinf.com\/alt-news\/newswire\/7-years-of-fbi-data-corporate-info-ssns-names-of-aids-patients-exposed-rt-usa-news\/","title":{"rendered":"7 years of FBI data, corporate info, SSNs &#038; names of AIDS patients exposed \u2014 RT USA News"},"content":{"rendered":"<p>        A trove of unprotected data including FBI investigations into corporations like AT&amp;T, Goldman Sachs, and Lehman Brothers, along with personal information, has been exposed in a data leak by the Oklahoma Securities Commission.<\/p>\n<div>\n<p>Three terabytes of data \u2013 millions of files \u2013 were left on a server with no password protection, freely available to anyone who stumbled across them, according to cybersecurity researchers Greg Pollock and Chris Vickery at cybersecurity firm <a href=\"https:\/\/www.upguard.com\/breaches\/rsync-oklahoma-securities-commission\" target=\"_blank\" rel=\"noopener noreferrer\">UpGuard<\/a>.<\/p>\n<div class=\"rtcode\">\n<blockquote class=\"twitter-tweet\" data-lang=\"en\">\n<p lang=\"en\" dir=\"ltr\">New report this morning from my team within <a href=\"https:\/\/twitter.com\/UpGuard?ref_src=twsrc%5Etfw\">@UpGuard<\/a>. The Oklahoma Department of Securities exposed an rsync host to the public internet with no username or password required to download. Mountains of broker PII and investigation files. <a href=\"https:\/\/t.co\/BwnaImRdtv\">https:\/\/t.co\/BwnaImRdtv<\/a><\/p>\n<p>\u2014 Chris Vickery (@VickerySec) <a href=\"https:\/\/twitter.com\/VickerySec\/status\/1085580860269555712?ref_src=twsrc%5Etfw\">January 16, 2019<\/a><\/p><\/blockquote>\n<\/div>\n<p>The files belonged to the Oklahoma Securities Commission, the government agency that regulates all financial securities business in the state. Among them were FBI files dating back seven years, covering cases open since the 1980s.<\/p>\n<p>These documents included spreadsheets, interviews with witnesses, bank records, and emails and letters from agents, witnesses, and subjects. Major companies involved with these cases included AT&amp;T, Goldman Sachs, and Lehman Brothers.<\/p>\n<p>Personal information on around ten thousand brokers was also exposed, including their social security numbers. Life insurance information, including names of AIDS patient and T cell counts was also revealed.<\/p>\n<div class=\"read-more\">\n<p>Read more<\/p>\n<p>    <a class=\"read-more__link\" href=\"http:\/\/www.rt.com\/news\/449028-largest-data-breach-in-history\/\" target=\"_blank\"><\/p>\n<picture><!--[if IE 9]><video style=\"display: none;\"><![endif]--><source media=\"(-webkit-min-device-pixel-ratio: 2) and (min-resolution: 120dpi)\" data-srcset=\"&#10;                            https:\/\/cdni.rt.com\/files\/2019.01\/xxs\/5c407aa2fc7e9352268b459e.jpeg 560w,&#10;                            https:\/\/cdni.rt.com\/files\/2019.01\/xs\/5c407aa2fc7e9352268b459e.jpeg 640w,&#10;                            https:\/\/cdni.rt.com\/files\/2019.01\/thumbnail\/5c407aa2fc7e9352268b459e.jpeg 920w,&#10;                            https:\/\/cdni.rt.com\/files\/2019.01\/m\/5c407aa2fc7e9352268b459e.jpeg 1080w,&#10;                            https:\/\/cdni.rt.com\/files\/2019.01\/l\/5c407aa2fc7e9352268b459e.jpeg 1536w,&#10;                            https:\/\/cdni.rt.com\/files\/2019.01\/article\/5c407aa2fc7e9352268b459e.jpeg 1960w,&#10;                            https:\/\/cdni.rt.com\/files\/2019.01\/xxl\/5c407aa2fc7e9352268b459e.jpeg 2480w&#10;                        \" srcset=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAABAAAAAJCAQAAACRI2S5AAAAEElEQVR42mNkIAAYRxWAAQAG9gAKqv6+AwAAAABJRU5ErkJggg==\"><source data-srcset=\"&#10;                            https:\/\/cdni.rt.com\/files\/2019.01\/xxs\/5c407aa2fc7e9352268b459e.jpeg 280w,&#10;                            https:\/\/cdni.rt.com\/files\/2019.01\/xs\/5c407aa2fc7e9352268b459e.jpeg 320w,&#10;                            https:\/\/cdni.rt.com\/files\/2019.01\/thumbnail\/5c407aa2fc7e9352268b459e.jpeg 460w,&#10;                            https:\/\/cdni.rt.com\/files\/2019.01\/m\/5c407aa2fc7e9352268b459e.jpeg 540w,&#10;                            https:\/\/cdni.rt.com\/files\/2019.01\/l\/5c407aa2fc7e9352268b459e.jpeg 768w,&#10;                            https:\/\/cdni.rt.com\/files\/2019.01\/article\/5c407aa2fc7e9352268b459e.jpeg 980w,&#10;                            https:\/\/cdni.rt.com\/files\/2019.01\/xxl\/5c407aa2fc7e9352268b459e.jpeg 1240w&#10;                        \" srcset=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAABAAAAAJCAQAAACRI2S5AAAAEElEQVR42mNkIAAYRxWAAQAG9gAKqv6+AwAAAABJRU5ErkJggg==\"><!--[if IE 9]><\/video><![endif]--><img decoding=\"async\" alt=\"Over 770 million email addresses shared online in largest data breach in history\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAABAAAAAJCAQAAACRI2S5AAAAEElEQVR42mNkIAAYRxWAAQAG9gAKqv6+AwAAAABJRU5ErkJggg==\" data-sizes=\"auto\" data-src=\"https:\/\/cdni.rt.com\/files\/2019.01\/xxs\/5c407aa2fc7e9352268b459e.jpeg\" class=\"read-more__cover lazyload\"\/><\/source><\/source><\/picture><!-- noscript pattern --><noscript><br \/>\n                    <img decoding=\"async\" src=\"https:\/\/cdni.rt.com\/files\/2019.01\/xxs\/5c407aa2fc7e9352268b459e.jpeg\" alt=\"File photo: \u00a9 Global Look Press \/ DPA \/ Sebastian Gollnow\"\/><\/noscript><\/p>\n<p>    <\/a>\n<\/div>\n<p><em>\u201cIt represents a compromise of the entire integrity of the Oklahoma department of securities\u2019 network,\u201d<\/em> UpGuard\u2019s head of research Chris Vickery told <a href=\"https:\/\/www.forbes.com\/sites\/thomasbrewster\/2019\/01\/16\/massive-oklahoma-government-data-leak-exposes-7-years-of-fbi-investigations\/#6e37cc256e11\" target=\"_blank\" rel=\"noopener noreferrer\">Forbes<\/a>. <em>\u201cIt affects an entire state level agency\u2026 It\u2019s massively noteworthy.\u201d<\/em><\/p>\n<p>Hackers interested in the files could have acquired them with minimal effort. The server they were stored on was not password protected, and could have been identified with readily available software that scans the internet for such servers. Within the server, the UpGuard team found further vulnerabilities. Passwords for agency computers were stored there, and encrypted files were stored in the same folders as unencrypted versions.<\/p>\n<p>Once the breach was discovered, the data was transferred to a secure server. But, UpGuard cannot tell who may have accessed it in the interim. Vickery told Forbes that the commission\u2019s response was <em>\u201cirresponsible,\u201d<\/em> as the OSC seemed uninterested in checking what had been done with the data.<\/p>\n<p>The Oklahoma Securities Commission is not the only government department to be caught with its pants down in recent years. A database of information on 191 million voters in all 50 states was left open to the public on an unconfigured server in 2015. In a similar case in 2011, the Texas Comptroller\u2019s Office admitted that it had inadvertently stored 3.5 million Texans\u2019 personal information on a publicly accessible state server.<\/p>\n<p>The corporate world is also rife with similar stories. Last April, <a href=\"https:\/\/www.rt.com\/usa\/424620-48-million-social-leaked\/\" target=\"_blank\" rel=\"noopener noreferrer\">data<\/a> from 48 million social media users was left in an unsecured Amazon server by LocalBlox, a data analytics company. In December, Level One Robotics, a company that provides robots for the auto industry, left data on an unsecure server. Auto giants Volkswagen, Chrysler, Ford, Toyota, General Motors and Tesla all had confidential data exposed in the <a href=\"https:\/\/www.upguard.com\/breaches\/short-circuit-how-a-robotics-vendor-exposed-confidential-data-for-major-manufacturing-companies\" target=\"_blank\" rel=\"noopener noreferrer\">leak<\/a>.<\/p>\n<p><strong><em>Think your friends would be interested? Share this story!<\/em><\/strong><\/p>\n<\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Via <a href=\"https:\/\/www.rt.com\/usa\/449062-fbi-data-leak-oklahoma\/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=RSS\">RT<\/a>. This piece was reprinted by <a href=\"http:\/\/rinf.com\">RINF Alternative News<\/a> with permission or license.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A trove of unprotected data including FBI investigations into corporations like AT&amp;T, Goldman Sachs, and Lehman Brothers, along with personal information, has been exposed in a data leak by the Oklahoma Securities Commission. Three terabytes of data \u2013 millions of files \u2013 were left on a server with no password protection, freely available to anyone [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":393698,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[519],"tags":[],"class_list":{"0":"post-393697","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-newswire"},"_links":{"self":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/posts\/393697","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/comments?post=393697"}],"version-history":[{"count":0,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/posts\/393697\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/media\/393698"}],"wp:attachment":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/media?parent=393697"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/categories?post=393697"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/tags?post=393697"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}