Adama City Government Exposes 29 GB of Sensitive Ethiopian Citizens' Data
Adama City Government in Ethiopia exposed over 29 GB of sensitive citizen data due to a misconfigured cloud server. The breach includes personal identification documents, financial records, and medical information of residents, posing serious privacy and security risks for those affected.
背景メモ
- 本記事が報じたのは、エチオピア第2の都市アダマ市の行政システムで発生した大規模データ漏洩。発見者はSecurity Chuというパキスタンのサイバーセキュリティ研究チームで、専門は政府・公共機関の脆弱性調査。
- 29GBのデータには市民の氏名、電話番号、居住地住所、出生証明書、家族構成の詳細、障害者登録情報、低所得者支援プログラムの受給記録などが含まれていた。
- Security Chuは2025年6月に脆弱性を発見し、即座にエチオピア政府のコンピュータ緊急対応チーム(ET-CERT)に報告。問題は同年9月に修正されたが、データが暴露されていた期間は約3ヶ月に及ぶ。
- 発見された脆弱性は「不適切なアクセス制御(Broken Access Control)」—認証なしにデータベースにアクセス可能な状態だった。これはOWASP(アプリケーションセキュリティの国際標準)のTop 10脆弱性の中でも最も深刻なカテゴリに分類される。