August 5th, 2024

Voter Documents Leaked Online

A breach involving 13 unsecured databases has exposed the personal information of 4.6 million American voters, raising concerns about identity theft, voter fraud, and election interference.

Read original articleLink Icon
Voter Documents Leaked Online

The personal information of 4.6 million American voters has been leaked online due to a breach involving 13 unsecured databases. The exposed data includes voter records, ballots, and sensitive personally identifiable information (PII) such as social security numbers, driver's license numbers, and voter ID numbers. Cybersecurity researcher Jeremiah Fowler discovered the breach and traced it back to Platinum Technology Resource, a company that provides election-related services. The databases were initially found to be unprotected, raising concerns about potential identity theft, voter fraud, and election interference. Although the databases have since been restricted, the duration of their exposure and the extent of unauthorized access remain unclear. Fowler noted that only an internal audit could reveal any suspicious activity. The leaked information could be exploited for malicious purposes, including mass disinformation campaigns or voter intimidation, particularly if accessed by foreign entities or political activists. Additionally, the breach could lead to legal complications for affected voters if their identities are misused to cast ballots. Fowler emphasized the importance of cybersecurity best practices for organizations managing sensitive information, including the use of unique database naming conventions to prevent unauthorized access. The incident highlights ongoing vulnerabilities in the management of voter data and the potential risks to electoral integrity.

Related

Ticketmaster has begun warning customers about data breach

Ticketmaster has begun warning customers about data breach

Ticketmaster notifies customers of a data breach involving personal information theft. 1.3 terabytes of data were compromised and sold on the dark web. Snowflake denies involvement. Ticketmaster enhances security measures.

AT&T says hackers stole records of nearly all cellular customers calls and texts

AT&T says hackers stole records of nearly all cellular customers calls and texts

Hackers accessed AT&T's system, obtaining call and text records from May to Oct. 2022 and Jan. 2023. The breach did not expose content or personal data but included sensitive phone numbers. AT&T is collaborating with law enforcement to investigate and enhance security measures. Senator Wyden highlighted the need for accountability in data breaches.

Hackers Steal Phone, SMS Records for Nearly All AT&T Customers

Hackers Steal Phone, SMS Records for Nearly All AT&T Customers

Hackers accessed AT&T's systems, compromising phone call and text records for 110 million customers. The breach revealed tower locations but not personal data. AT&T delayed disclosure due to security concerns.

The biggest data breaches in 2024: 1B stolen records and rising

The biggest data breaches in 2024: 1B stolen records and rising

In 2024, data breaches exposed over 1 billion records. AT&T, Change Healthcare, and Synnovis faced breaches, impacting customer data security. Snowflake's involvement in multiple breaches raises concerns about data protection.

FBI, CISA remind US voters that DDoS attacks can't touch election systems

FBI, CISA remind US voters that DDoS attacks can't touch election systems

US law enforcement and cybersecurity agencies reassured voters that DDoS attacks won't compromise election integrity, despite recent outages. They emphasized reliance on official sources and addressed concerns about foreign influence operations.

Link Icon 2 comments
By @ipython - 6 months
Nice. Combine this with Georgia’s online portal to cancel a voters registration[1] which only requires a name, dob, county, and last four of ssn and you have disenfranchisement at scale!

[1] https://sos.ga.gov/page/voter-registration-cancellation

By @gradientsrneat - 6 months
iirc voter registration records can be legally obtained in bulk, presumably containing names and addresses but I'm not sure if it's the full record. Presumably, such records are used by tools like ResistBot to notify you when your voting registration was removed.

Voting records are another level on top of that and I can see how that would be used for voter intimidation. Voting used to be spoken aloud very early in the US republic. It changed for good reason.