True customers’ identity records exposed in data leak

In this article (5)
Thailand’s True Corp has fixed a data leak involving the exposure of identity records on up to around 45,000 of its customers.
Security researcher Niall Merrigan discovered personal data on customers of True Corp’s e-commerce subsidiary iTrueMart (now WeMall) stored in a public-facing Amazon S3 bucket in March.
The 32GB data cache included 45,736 files, consisting mainly of JPG and PDF scans of identity documents including scanned ID cards, drivers licenses and possibly passports.
In a blog post, Merrigan said he informed True Corp’s mobile unit True Move H about the breach on March 10, but the company took no action until he went to the media in early April. The files were finally made private on April 12.
Merrigan indicated that True Corp seems to be misrepresenting the incident as a hack, but there was no security on the data bucket and anybody could have found and downloaded all the files.
Telecoms regulator NBTC is investigating the incident, and may impose penalties on True Corp for exposing customer information. The stored identity records may have been collected as part of the Thai government’s mandatory SIM registration scheme, which has already been a target of identity thieves and has been opposed by privacy advocates.
Questions & Answers
Q.What kind of data was exposed in the True Corp leak?
What kind of data was exposed in the True Corp leak?
The data cache, amounting to 32GB, mainly contained JPG and PDF scans of identity documents. These included scanned ID cards, drivers' licences, and potentially passports belonging to customers.
Q.When was True Corp first notified about the data breach?
When was True Corp first notified about the data breach?
Security researcher Niall Merrigan informed True Corp's mobile unit, True Move H, about the breach on March 10. However, the company did not take action until he contacted the media.
Q.How did the data become exposed?
How did the data become exposed?
The data was stored in a public-facing Amazon S3 bucket without any security. This meant anyone could have found and downloaded all the files, as it was not a hack.
Q.Is True Corp facing any consequences for this incident?
Is True Corp facing any consequences for this incident?
The telecoms regulator, NBTC, is currently investigating the incident. It is possible they may impose penalties on True Corp for exposing its customers' information.
Reader pulse
True Corp's handling of this data leak was:
21,922 votes so far