News: 1584531009

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Small business loans app blamed as 500,000 financial records leak out of ... you guessed it, an open S3 bucket

(2020/03/18)


A now-defunct mobile app for loaning money to small business owners has been pinned down as the source of an exposed archive containing roughly 500,000 personal and business financial records.

The research team at vpnMentor said it [1]traced an exposed database of financial records back to a former Android/iOS app called MCA Wizard, developed jointly by Advantage Capital Funding and Argus Capital Funding back in 2018.

The app, which has been pulled from both the Google and Apple stores, was apparently designed to allow businesses to apply for and manage merchant cash advance (MCA) short-term loans.

According to the vpnMentor crew, the app stored documents like bank statements, photocopies of driver's licenses, credit checks, and even tax and social security information – all in an unsecured AWS S3 storage bucket. Though the app was defunct, that bucket remained online and configured for public access.

"These files didn't just compromise the privacy and security of Advantage and Argus, but also the customers, clients, contractors, employees, and partners," vpnMentor noted in its report.

While the exposure of information on thousands of people and small businesses is bad enough, there at least seems to be nothing to indicate that the database was found by criminals prior to being reported and taken down by AWS on January 9, more than two weeks after being discovered by the white hat researchers.

Interestingly, although the app is no longer available, the researchers noted that new documents were being added to the storage instance right up until its removal, suggesting another application could also be using the bucket.

More worrisome, though, is that the researchers were unable to reach either of the companies credited with developing the app ( The Register was also unable to get comment from either Argus or Advantage), and they might in fact not even really be separate entities.

"While the database's URL contained 'MCA Wizard,' most files had no relation to the app. Instead, they originated from both Advantage and Argus. Furthermore, throughout our research, files were still being uploaded to the database, even though MCA Wizard seems to have been closed down," vpnMentor said.

"Information on all three entities is scarce, but they appear to be owned and operated by the same people. However, there is no clear connection between MCA Wizard and the two companies that own it anywhere online."

Business owners and others who used the app and are concerned about their data being misused are advised to keep a close eye on their bank statements and, if they notice unauthorised activity or new accounts, to report this and consider a credit freeze. ®



[1] https://www.vpnmentor.com/blog/report-mca-wizard-leak/

Anonymous Coward

Why are these things called buckets?

Dave Pickles

So we can say [1]"There's a hole in my bucket..."

[1] https://en.wikipedia.org/wiki/There%27s_a_Hole_in_My_Bucket

Aristotles slow and dimwitted horse

Dear Coward...

Dear Coward...

stiine

A hole.

Ok, the lesson to learn here . .

Pascal Monett

. . is that it is time to stop trusting small startups with your private data.

Yeah, I know, that is going to put a crimp on startups that propose money. In the meantime, we need a certification that proves that the startup knows what security is and knows how to manage cloud accounts.

I know, I'm dreaming. Just don't trust financial startups that don't have a banking charter.

Re: Ok, the lesson to learn here . .

IGotOut

Is Equifax a start up?

Re: Ok, the lesson to learn here . .

Down not across

Just don't trust financial startups that don't have a banking charter.

Sadly entities with a banking charter are not necessarily any more trustworthy.

Re: Ok, the lesson to learn here . .

HildyJ

Given that Barklay's leaky bucket just hit the news 5 days ago and BT seems to be using a wicker basket instead of a bucket, I think you should say companies, not small financial startups.

Re: Ok, the lesson to learn here . .

Snake

It's quite sad, really. When I set up (our) S3 bucket, obscure as some of the optional configurations were, I made it a point to go through them, learn what they did, and set accordingly. As a result my bucket was 'Can be public' from Day 1 of the privacy testing tools rollout, a decent setting.

So some "tech" support, with far more responsibilities and (supposedly) far more training than me, yet far less real-world intelligence, pushes a few buttons and stamps "Done!" to the project. If they are assigning the project to the PFY then they only have themselves to blame for not following up on assurance; if the BOFH is causing these muck-ups then one must, frankly, question their compensation levels.

At least

Androgynous Cow Herd

For once no one had to stand up and fib "Your privacy is important to Us"

Once again...

YetAnotherJoeBlow

Yet another reason to hold CEOs personally accountable for both civil and criminal matters for preventable information disclosure. (ie a permissions problem.)

Are S3 buckets insecure by default?

Mike Lewis

Woudn't it be better to make them secure by default instead?

Re: Are S3 buckets insecure by default?

Anonymous Coward

No, they are incredibly secure by default. You have to physically uncheck 4 checkboxes just to make the bucket and subsequent uploaded files publicly accessible.

"Just out of curiosity does this actually mean something or have some
of the few remaining bits of your brain just evaporated?"
-- Patricia O Tuama, rissa@killer.DALLAS.TX.US