OCR Labs exposed credentials tied to banking clients in misconfigured file
- Organization
- OCR Labs
- Exploit
- Misconfiguration
- Industry
- Identity Verification
Cybernews researchers reported in April 2023 that OCR Labs, a London based digital identity verification vendor, had left a configuration file publicly accessible on servers for its IDKit product. The file was found on March 8, 2023. It contained credentials rather than customer records.
According to the research, the exposed environment file held database credentials, AWS and SQS access keys, application tokens and API keys, among them keys for the company's liveness detection service, for Experian credit reporting and for its Engine v4 know your customer system. Researchers said an attacker holding those keys could in principle have reached backend infrastructure serving OCR Labs clients, opening the way to identity theft, fraudulent account creation or lateral movement.
The clients named in the reporting were the Australian institutions QBANK, Defence Bank and MA Money, and in the United Kingdom Bloom Money, Admiral Money and the recruitment firm Reed.
OCR Labs corrected the misconfiguration after being notified and disputed how the finding was characterised. The company told Biometric Update that there was never a data leak or breach in any of its systems, that the exposed material belonged to unused demo and non-production environments, and that the keys were for offline systems. It said an internal investigation concluded there was no risk to the security of client data and that it had notified the clients concerned. No evidence emerged that anyone other than the researchers accessed the file.