Dutch COVID testing lab CoronaLab exposed 1.3 million records in open database
- Organization
- Microbe & Lab (CoronaLab)
- Exploit
- Misconfiguration
- Industry
- Medical Laboratory
Security researcher Jeremiah Fowler reported finding a database with no password protection holding roughly 1.3 million records that carried the branding of CoronaLab.eu, a COVID-19 testing service owned by the Amsterdam medical laboratory Microbe & Lab. CoronaLab was one of the largest commercial test providers in the Netherlands and had been listed by the US Embassy in the Netherlands as a recommended test provider.
Fowler put the contents at 118,441 test certificates, 506,663 appointment records and 660,173 testing samples, alongside QR codes linking to appointment details and a small quantity of internal application files. Individual records included patient names, dates of birth, nationality, email addresses and passport numbers, together with test results and the price, location and type of each test.
According to Fowler, the database stayed publicly reachable for about three weeks. He said repeated responsible disclosure notices and several phone calls to CoronaLab and Microbe & Lab went unanswered, and that access was only closed after he contacted the cloud hosting provider directly.
CoronaLab responded publicly on January 29, 2024, saying unlawful access had been gained to a backup of data through a former IT supplier. The company said it had reported the incident to the Dutch data protection authority and was notifying affected individuals, and that it had no indication the data had been misused.