Inspiring Vacations left 112,000 travel records in an open cloud bucket
- Organization
- Inspiring Vacations
- Exploit
- Misconfiguration
- Industry
- Travel
Security researcher Jeremiah Fowler found an unsecured cloud storage repository belonging to Inspiring Vacations, a Melbourne-based travel agency, and reported the finding through Website Planet. The store was not password protected and held 112,605 records totalling 26.8 gigabytes. Cyber Daily noted that the record count does not necessarily represent the number of customers affected, and Inspiring Vacations said publicly on January 11, 2024 that the number of individuals actually at risk was significantly smaller than media reports suggested.
The exposed files covered a wide range of customer material. They included roughly 1,000 identity documents such as high-resolution passport images and travel visa certificates, 48 Excel spreadsheets listing 13,684 customers with names, email addresses, trip costs and destinations, about 24,000 itinerary and e-ticket documents, some of which showed partial payment card numbers, around 17,000 tax invoices issued to partners and affiliates, and CVs containing personal contact details. Most of the individuals identified were Australian, but identity documents belonging to citizens of New Zealand, the United Kingdom and Ireland were also present.
The cause was reported as an incorrectly configured Amazon Web Services storage bucket that allowed public access. Inspiring Vacations secured the data after Fowler's disclosure.
The company said it took cyber security and the protection of its data seriously, that it had launched an investigation with external assistance, that it had contacted staff and customers in early December 2023 to announce that investigation, and that it had contacted the Office of the Australian Information Commissioner. On January 11, 2024 the company said all at-risk individuals had by then been provided with specific details about the data involved and the steps they could take. There was no public indication that anyone other than the researcher had accessed the files.