MC2 Data left 2.2TB background check database exposed online
- Organization
- MC2 Data
- Exploit
- Human Error
- Industry
- Data Brokerage
MC2 Data, a US background check company, left a 2.2 terabyte database sitting on the open internet with no password protection. Researchers at Cybernews said they found the unsecured instance on August 7, 2024 and made the finding public in late September, after which the data was secured.
The exposed store held 106,316,633 records containing personal information on an estimated 100 million or more people in the United States. Fields included full names, dates of birth, home addresses, phone numbers, email addresses, IP addresses and user agent strings, encrypted passwords, partial payment details, employment histories, property and legal records, and information about relatives, neighbors and associates of the people profiled.
The exposure was not limited to the subjects of background checks. Records for 2,319,873 subscribers to MC2's services were also readable, a group that includes employers, landlords and others who had run checks through the company. MC2 operates a set of consumer facing sites including PrivateRecords.net, PrivateReports, PeopleSearcher, ThePeopleSearchers and PeopleSearchUSA.
Researchers attributed the exposure to human error rather than an intrusion, since no attacker had to defeat any control to read the data. MC2 Data did not respond to requests for comment from Infosecurity Magazine, and had issued no public statement about the incident as of early October 2024. Class action lawyers began soliciting claims within days.