• Latest
  • Trending
  • All
  • Market Updates
  • Cryptocurrency
  • Blockchain
  • Investing
  • Commodities
  • Personal Finance
  • Technology
  • Business
  • Real Estate
  • Finance
Money transfer app Duc exposed thousands of driver’s licenses and passports to the open web

Money transfer app Duc exposed thousands of driver’s licenses and passports to the open web

April 3, 2026
Stocks making the biggest moves midday: TSLA, NEXT, GM, DAL

Stocks making the biggest moves midday: TSLA, NEXT, GM, DAL

April 3, 2026
What is the distribution of forecasts for the US NFP?

What is the distribution of forecasts for the US NFP?

April 3, 2026
Drift Seeks Contact With The Hacker After $280M Exploit

Drift Seeks Contact With The Hacker After $280M Exploit

April 3, 2026
CFTC Lets US Firms Keep Trading Swaps on Two More UK Platforms After Brexit

CFTC Sues Arizona, Connecticut, and Illinois for Overreach on Prediction Markets

April 3, 2026
Bitcoin analysis and price prediction score today at investingLive.com

Bitcoin analysis and price prediction score today at investingLive.com

April 3, 2026
Bitcoin Could Be Taiwan’s Lifeline In Conflict, Think Tank Suggests

Bitcoin Could Be Taiwan’s Lifeline In Conflict, Think Tank Suggests

April 3, 2026
Effect of Tokenization on Financial Stability Not Clear

Effect of Tokenization on Financial Stability Not Clear

April 3, 2026
My Wife Took The Kids And Left Me – Thoughts Appreciated

My Wife Took The Kids And Left Me – Thoughts Appreciated

April 3, 2026
Dogecoin Admits Its A Joke Alright, But You Can Take The 16100% Gains Seriously

Dogecoin Admits Its A Joke Alright, But You Can Take The 16100% Gains Seriously

April 3, 2026
OpenAI Acquires Tech Talk Show ‘TBPN’—and Buys Itself Some Positive News

OpenAI Acquires Tech Talk Show ‘TBPN’—and Buys Itself Some Positive News

April 3, 2026
Brick vs. Bloom Card: I tested both for my screen addiction, and the winner depends on you

Brick vs. Bloom Card: I tested both for my screen addiction, and the winner depends on you

April 3, 2026
Soft Manager – Trading Ideas – 5 August 2025

5 Revenge Trading Triggers That Blow Accounts Overnight – My Trading – 2 April 2026

April 3, 2026
Friday, April 3, 2026
No Result
View All Result
InvestorNewsToday.com
  • Home
  • Market
  • Business
  • Finance
  • Investing
  • Real Estate
  • Commodities
  • Crypto
  • Blockchain
  • Personal Finance
  • Tech
InvestorNewsToday.com
No Result
View All Result
Home Technology

Money transfer app Duc exposed thousands of driver’s licenses and passports to the open web

by Investor News Today
April 3, 2026
in Technology
0
Money transfer app Duc exposed thousands of driver’s licenses and passports to the open web
492
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter


A publicly accessible Amazon-hosted storage server allowed anybody with an online browser to entry probably tons of of hundreds of individuals’s private information while not having a password. This included driver’s licenses, passports, and different private data collected by the Duc App, a money-transfer service owned by Toronto-based Duales.

The Canadian fintech firm mentioned it resolved the information publicity on Tuesday after TechCrunch alerted its chief government that one of many firm’s cloud storage servers was publicly itemizing its contents, with out a password.

The information was additionally saved unencrypted, that means anybody with a hyperlink to the information was capable of view it in full.

Anurag Sen, a safety researcher at CyPeace who found the safety lapse earlier within the week, contacted TechCrunch in an effort to inform the information’s proprietor. Sen mentioned that anybody may view and obtain the information utilizing their browser simply by figuring out the easy-to-guess internet deal with of the storage server.

Based on Sen, the Amazon-hosted storage server listed over 360,000 recordsdata containing government-issued paperwork and different data utilized by prospects to confirm their identification via “know your buyer” checks. These recordsdata included user-uploaded selfies to show their real-world likeness.

TechCrunch couldn’t verify the exact variety of uncovered driver’s licenses and passports; nonetheless, a number of folders within the uncovered bucket every contained tens of hundreds of user-uploaded recordsdata, a sampling of which listed driver’s licenses, passports, and selfies.

Duales touts its app as a method for customers to ship cash to different customers, together with abroad in Cuba and elsewhere. Its Android app itemizing on the Google Play app retailer exhibits greater than 100,000 person downloads to this point.

The recordsdata, which dated again to September 2020 and had been being uploaded each day, additionally contained spreadsheets itemizing buyer names, dwelling addresses, and the dates, occasions, and particulars of their transactions.

When reached by e mail, Duales chief government Henry Martinez González instructed TechCrunch that the information was saved on a “staging web site,” referring to an internet site used primarily for testing, however didn’t clarify why prospects’ private data was publicly accessible in the identical database.

“All protections are in place,” Martinez González mentioned. “We’re notifying the suitable events. We have now not contracted any companies from you.”

After TechCrunch emailed the corporate, the recordsdata on the storage server had been made inaccessible, although an inventory of the server’s contents continues to be seen.

Martinez González wouldn’t say if the corporate had the technical means, equivalent to logs, to find out who or how many individuals accessed the information. 

Duc App’s web site appeared briefly down on Thursday, and displayed a “unhealthy gateway” error.

It’s not clear how or for what purpose Duales left its Amazon-hosted storage server publicly open to the web. In recent times, Amazon has added safety checks to forestall customers from inadvertently exposing their information to the web after a collection of high-profile incidents the place a number of company giants, together with a U.S. spy company, printed delicate information to the net as a consequence of misconfigurations.

When reached by TechCrunch as a part of our outreach to contact the app’s proprietor, Canada’s privateness regulator mentioned it was searching for extra data from the corporate.

“The Workplace of the Privateness Commissioner of Canada has reached out to the corporate to acquire extra data and decide subsequent steps,” a spokesperson for the regulator instructed TechCrunch by e mail, declining to remark additional.

Duc App is the most recent app in an inventory of current safety lapses involving the publicity of different individuals’s delicate identification information. This information publicity comes as apps and web sites are more and more requiring their customers to add their government-issued paperwork to confirm who they are saying they’re however with out taking sufficient steps to safe the information that they accumulate. 

Final yr, in style app TeaOnHer uncovered hundreds of its customers’ passports and driver’s licenses, which the app required customers to add earlier than permitting them into the app’s gated neighborhood. Discord final yr additionally confirmed an information breach affecting round 70,000 government-issued paperwork uploaded by customers who sought to confirm their age, amid a worldwide effort to enact on-line age checking legal guidelines.



Source link

Tags: AppDriversDucExposedLicensesmoneyopenpassportsthousandstransferWeb
Share197Tweet123
Previous Post

CFTC Sues Arizona, Connecticut, and Illinois for Overreach on Prediction Markets

Next Post

Drift Seeks Contact With The Hacker After $280M Exploit

Investor News Today

Investor News Today

Next Post
Drift Seeks Contact With The Hacker After $280M Exploit

Drift Seeks Contact With The Hacker After $280M Exploit

  • Trending
  • Comments
  • Latest
Want a Fortell Hearing Aid? Well, Who Do You Know?

Want a Fortell Hearing Aid? Well, Who Do You Know?

December 3, 2025
Private equity groups prepare to offload Ensemble Health for up to $12bn

Private equity groups prepare to offload Ensemble Health for up to $12bn

May 16, 2025
Lars Windhorst’s Tennor Holding declared bankrupt

Lars Windhorst’s Tennor Holding declared bankrupt

June 18, 2025
The human harbor: Navigating identity and meaning in the AI age

The human harbor: Navigating identity and meaning in the AI age

July 14, 2025
Why America’s economy is soaring ahead of its rivals

Why America’s economy is soaring ahead of its rivals

0
Dollar climbs after Donald Trump’s Brics tariff threat and French political woes

Dollar climbs after Donald Trump’s Brics tariff threat and French political woes

0
Nato chief Mark Rutte’s warning to Trump

Nato chief Mark Rutte’s warning to Trump

0
Top Federal Reserve official warns progress on taming US inflation ‘may be stalling’

Top Federal Reserve official warns progress on taming US inflation ‘may be stalling’

0
Stocks making the biggest moves midday: TSLA, NEXT, GM, DAL

Stocks making the biggest moves midday: TSLA, NEXT, GM, DAL

April 3, 2026
What is the distribution of forecasts for the US NFP?

What is the distribution of forecasts for the US NFP?

April 3, 2026
Drift Seeks Contact With The Hacker After $280M Exploit

Drift Seeks Contact With The Hacker After $280M Exploit

April 3, 2026
Money transfer app Duc exposed thousands of driver’s licenses and passports to the open web

Money transfer app Duc exposed thousands of driver’s licenses and passports to the open web

April 3, 2026

Live Prices

© 2024 Investor News Today

No Result
View All Result
  • Home
  • Market
  • Business
  • Finance
  • Investing
  • Real Estate
  • Commodities
  • Crypto
  • Blockchain
  • Personal Finance
  • Tech

© 2024 Investor News Today