Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

1M Passports Leaked Online

A database containing approximately one million passport records from 18 countries was leaked online. The exposed data includes passport images, nationalities, and personal details such as full names and dates of birth, raising significant cybersecurity and privacy concerns.

Background

- Bruce Schneier is a world-renowned security technologist, author, and public-interest cryptographer. His blog is a highly respected source for news and analysis on computer security, privacy, and surveillance. - This post reports that a database containing roughly one million passport images (scanned photos of the data page, not just numbers) was found exposed on the open internet without a password. - The leak appears to come from a travel-industry data aggregator, not a government. Such aggregators collect passport data from airlines, hotels, and visa-processing services to verify travelers. - Passport images are far more dangerous than credit-card numbers: they cannot be easily cancelled or reissued, and they enable identity theft, synthetic identity fraud, and physical border-crossing fraud. - The core issue: massive databases of highly sensitive identity documents are assembled by private companies with weak security, and the public has no way to know or consent to their existence, let alone protect themselves after a breach.