SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Yet Another AWS Config Fumble: Time Warner Cable Exposes 4 Million Subscriber Records
Date    Monday September 11 2017, @02:51PM
Author    Fnord666
Topic   
from the another-day,-another-unsecured-database dept.
https://soylentnews.org/article.pl?sid=17/09/11/0137214

MrPlow writes:

Submitted via IRC for SoyCow5389

Records of roughly four million Time Warner Cable customers in the US were exposed to the public internet after a contractor failed to properly secure an Amazon cloud database.

Researchers with security company Kromtech said freelancers who handled web applications for TWC and other companies had left one of its AWS S3 storage bins containing seven years' worth of subscriber data wide open on the 'net. That data included addresses and contact numbers, information about their home gateways, and account settings.

Just before the weekend, Kromtech said the vulnerable AWS instance was operated by BroadSoft, a cloud service provider that had been using the S3 silos to hold the SQL database information that included customer records.

The researchers found that the database included information on four million TWC customers collected between November 26, 2010 and July 7, 2017. The exposed data included customer billing addresses, phone numbers, usernames, MAC addresses, modem hardware serial numbers, account numbers, and details about the service settings and options for the accounts.

A spokesperson for TWC parent company Charter said the telly giant was aware of the cockup, and is notifying the customers who were exposed.

Source: https://www.theregister.co.uk/2017/09/05/twc_loses_4m_customer_records/


Original Submission

Links

  1. "MrPlow" - https://soylentnews.org/~MrPlow/
  2. "Kromtech said" - https://mackeepersecurity.com/post/global-communication-software-left-massive-amount-of-data-online
  3. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=22161

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, Yet Another AWS Config Fumble: Time Warner Cable Exposes 4 Million Subscriber Records on 2024-03-29 08:06:11