News: 1686573251

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Lantum S3 bucket leak is prescription for chaos for thousands of UK doctors

(2023/06/12)


A UK agency for freelance doctors has potentially exposed personal details relating to 3,200 individuals via unsecured S3 buckets, which one expert said could be used to launch ID theft attacks or blackmail.

Lantum, an online locum doctor agency, had left the storage accessible on its old backend system, Network Locum, according to researchers. [1]Cybernews discovered the Amazon AWS S3 bucket, potentially exposing 98,000 files relating to thousands of individuals.

The security analysis company monitors various cloud blob storage to understand the potential for misconfiguration. In the process, it discovered the Lantum S3 bucket, which was accessible and indexed on some IoT search engines. The analysts said any malicious actor could have found the repository of personal data relating to the 2014-2016 period.

[2]

"We then tried to contact Lantum multiple times with no response. We have asked for NCSC help and were advised to report it to NHS too. However, after multiple attempts, we received no response," the researchers said. The bucket was closed almost immediately after the publication.

[3]

[4]

Files contain personal information of general practitioners using its services, including passport details, national insurance numbers, resumes, medical documents, professional certificates, payroll details and invoices. Lantum told Cybernews it complied with security standard ISO27001 and had been audited. ISO27001 covers controls that guide data storage.

The Register has offered Lantum the opportunity to comment. According to a statement given to doctors' news site Pulse, a spokesperson for Lantum said: "While this data may have been accessible to unauthorised individuals, there is currently no indication that data has been accessed and no reason to suspect that this is the case.

[5]

"We are, however, treating this matter as a potential data breach and will continue to liaise with any individuals who may be affected should more information be revealed by our investigations."

But one doctor with tech expertise was not reassured.

[6]Another security calamity for Capita: An unsecured AWS bucket

[7]T-Mobile US suffers second data theft within months

[8]McGraw Hill's S3 buckets exposed 100,000 students' grades and personal info

[9]AWS strains to make Simple Storage Service not so simple to screw up

Dr Marcus Baw, immediate past chair of Royal College of GPs Health Informatics Group, said the accessible information was personally sensitive and could leave affected doctors exposed. "Those are the kinds of details you would pick if you wanted to be in a very strong position to create a fake identity," he said.

As well as ID theft, there was a danger of blackmail as the records include details of complaints related to regulatory body the General Medical Council, many of which may be unproven or vexatious.

Baw warned it might take years for the details to resurface in the form of ID theft campaigns after the details have been traded on the dark web.

[10]

He said Lantum should be able to analyze downloads from the S3 buckets in question to asses if there had been any unusual activity, and notify the doctors affected.

"They need to admit it. They need to contact every doctor that has ever registered with them and say they are at risk and describe the magnitude of the risk. They could offer to pay underwriting companies to protect those affected against identity theft," Baw said.

Formerly known as Network Locum, [11]Lantum rebranded in 2017 . In 2022, Lantum announced it [12]received $15 million in funding from Finch Capital, Piton Capitol, Samos, and Cedar-Sinai Hospital. ®

Get our [13]Tech Resources



[1] https://healthnews.com/news/uk-healthcare-platform-lantum-leaked-98k-files/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZIdBH@CDCaessdzxy9nsDwAAAEE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZIdBH@CDCaessdzxy9nsDwAAAEE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZIdBH@CDCaessdzxy9nsDwAAAEE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZIdBH@CDCaessdzxy9nsDwAAAEE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2023/05/17/another_security_calamity_for_capita/

[7] https://www.theregister.com/2023/05/08/in_brief_security/

[8] https://www.theregister.com/2022/12/20/mcgraw_hills_s3_buckets_exposed/

[9] https://www.theregister.com/2022/12/14/aws_simple_storage_service_simplified/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZIdBH@CDCaessdzxy9nsDwAAAEE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://www.hospitalmanagement.net/news/newsnetwork-locum-rebranded-to-lantum-5873205/

[12] https://www.privateequitywire.co.uk/2022/03/29/313270/lantum-raises-usd15m-funding-round-led-finch-capital

[13] https://whitepapers.theregister.com/



wolfetone

As bad as this incident is, it's quite refreshing to hear of a company's press release not involve the phrase "We take our IT security/protection of our user data seriously".

But then it's a bit shit that they've effectively said "No one used it so gives a shit".

ChoHag

Same bullshit, different words.

> Lantum told Cybernews it complied with security standard ISO27001 and had been audited.

"there is currently no indication that data has been accessed"

Arthur the cat

because we have no way of knowing whether it was accessed or not.

Lack of consequences

demon driver

The main mistake is that nothing serious ever happens to those who run such businesses. After such an incident, the business should be expropriated and the owners plus the managers in charge should spend a long time in prison, banned from ever running a business again.

Is ISO 27001 relevant?

Anonymous Coward

Does ISO 27001 actually say anything that might affect whether a particular repository was secured?

Fortune: You will be attacked next Wednesday at 3:15 p.m. by six samurai
sword wielding purple fish glued to Harley-Davidson motorcycles.

Oh, and have a nice day!
-- Bryce Nesbitt '84