Unsecured database at Chile's Caja Los Andes exposed data on 10 million people
- Organization
- Caja Los Andes
- Exploit
- Misconfiguration
- Industry
- Financial Services
Caja Los Andes, the largest Family Allowance Compensation Fund in Chile, left an Apache Cassandra database reachable on the internet without authentication, exposing personal records on roughly 10 million people. That figure represents more than half of Chile's population.
Researchers at Cybernews found the database and published their findings in August 2024, attributing the exposure to a lack of authentication on the Cassandra instance rather than any intrusion. The records they described included home addresses, email addresses and other identifying details along with financial information tied to the fund's users.
Caja Los Andes was founded in 1953 and is Chile's leading social security and family allowance body, providing health insurance, pension services, loans and mortgages to workers and their families. TechRadar reported that the exposed dataset held more than double the roughly four million members the fund lists, which researchers took to mean it also covered family members and inactive or historical accounts.
Neither of the reports reviewed for this entry carried a statement from Caja Los Andes. The Cybernews research noted that Chilean data protection law allows fines reaching up to 4 percent of an organisation's annual income for a lapse of this kind. Both outlets described the leak as reaching more than half of Chile's population.