Physical security biz exposes 1.2M files via unprotected database
- Reference: 1715077807
- News link: https://www.theregister.co.uk/2024/05/07/uk_security_company_breach/
- Source link:
A researcher [1]says they stumbled upon a trove of data belonging to Amberstone Security, which included thousands of pictures of its guards as well as pictures of individuals suspected of offenses including shoplifting.
In total, 1,274,086 documents were exposed to the internet via a misconfigured database for an unknown length of time, we're told. It's unclear if the data had ever been accessed by anyone with malicious intent.
[2]
Amberstone Security offers surveillance, access control, and merchandise-protection products and services, as well as guards on 24-hour duty to customers.
[3]
[4]
Among the exposed data, which dates back to 2017, was a folder containing 99,151 snapshots of guards checking in for their shifts, either by using a picture of themselves, their ID cards, or both. The pictures taken of the ID cards displayed basic information such as their name, headshot, and the card's expiry date. In rare cases, it showed their signature too.
The ID cards were also issued by the Security Industry Authority (SIA), the UK's regulator for the private security industry. The cards do not have any biometric technology built into them and are basic, plastic ID cards that hypothetically could be fairly easily duped and abused.
[5]
Speaking to The Register , researcher Jeremiah Fowler, claimed the SIA told him there are plans to introduce biometry to the cards in the near future. However, there is no specific date for this.
"The exposure of SIA identification documents could pose a serious potential threat to public safety, personal privacy, and the integrity of security operations if misused by unauthorized individuals," said Fowler.
"One hypothetical example of a risk scenario would be if criminals used the exposed information such as the guard's names, photographs, and license numbers to impersonate security personnel or gain unauthorized access to a secure facility for criminal purposes. This could potentially lead to a [6]physical security breach , theft, vandalism, or – as a worst-case scenario – acts of terrorism."
[7]
Exposing a database in any case would present obvious privacy risks, and these are amplified if the exposed data ties an individual to a suspected crime, which was the case in this incident.
Fowler says the documents found in the exposed database showed images of suspected offenders either seemingly caught in the act via CCTV or photographed by security personnel afterward. Many images clearly depicted the suspects and were captioned with information such as their name, date of birth, and nature of their alleged offense.
In some cases, detailed descriptions of how a suspect operates were found, said Fowler. One man and his associates were known to frequent the Lakeside and Stratford shopping centers in the south east of England, for example, and apparently had a particular penchant for high-value men's suits.
The description contained details about how suspected offenders got away with the thefts, mentioning that they later return to the store and target young staff to complete a confusing process to obtain a cash refund on the stolen goods.
Similarly, spreadsheets were also filled with information about offenses, how they were committed, and whether violence was used or not.
[8]UK's Investigatory Powers Bill to become law despite tech world opposition
[9]Exposed: Chinese smartphone farms that run thousands of barebones mobes to do crime
[10]Amazon Ring sounds death knell for surveillance as a service
[11]UK policing minister urges doubling down on face-scanning tech
Swift response
A day after being alerted to the exposed database, Amberstone Security revoked public access to the database and informed Fowler that the blunder may have been caused by a third party.
"Thank you for bringing this to our attention, this is deeply concerning. I am investigating this with the supplier who developed and hosts the platform," a company rep told the researcher. "Please rest assured that we take data security seriously, and this will be investigated thoroughly."
The Register contacted Amberstone for a response and a spokesperson for parent company Argenbright Security Europe said: "Amberstone were made aware of a server configuration issue and immediately contained any risks. We have acted accordingly and in line with our regulatory obligations."
The identity of the third-party contractor was not specified by Amberstone Security. ®
Get our [12]Tech Resources
[1] https://www.websiteplanet.com/news/amberstone-breach-report/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZjpQHKCnUe@-XY@VV8jA@QAAAIs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjpQHKCnUe@-XY@VV8jA@QAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZjpQHKCnUe@-XY@VV8jA@QAAAIs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjpQHKCnUe@-XY@VV8jA@QAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2022/07/07/lock_down_your_piss_corridor/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZjpQHKCnUe@-XY@VV8jA@QAAAIs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2024/04/26/investigatory_powers_bill/
[9] https://www.theregister.com/2024/03/21/china_smartphone_farms/
[10] https://www.theregister.com/2024/01/25/amazon_ring_sounds_death_knell/
[11] https://www.theregister.com/2023/10/31/uk_police_minister_lfr/
[12] https://whitepapers.theregister.com/
Re: Only now? - 'Fire and Forget'
I went to a presentation by a senior executive just after I joined my last company. He said he liked the idea of 'fire and forget', which he took as something from the Vietnam war, when a missile could be fired and it would find its own way to the target, so the pilot could just forget it. Unfortunately the Western powers lost the Vietnam war, and the most appropriate quotation from that conflict is surely the response of the senior US General when asked to assess the situation after the Viet Minh had taken the last heights surrounding Phnom Penh " We're F**ked". Consternation from the assembled journalists, who wanted something they could print. But the general insisted "We're F**ked. They can kill us any time they want."
I am not a fan of 'fire and forget management.
Re: Only now? - 'Fire and Forget'
>the Viet Minh had taken the last heights surrounding Phnom Penh
The North Vietnames surrounded Cambodia's capital city with American forces in it? Is this about someone else or some other place, one that is surrounded by heights?
I wonder if, when a contractor is working on a building that Amberstone guard, they send along one of their security guards to oversee the job.
Defence in depth
"Thank you for bringing this to our attention...I am investigating who I can transfer blame for this to."
The scary thing is not that this was exposed to the internet (although that's bad enough) but that once you are inside the system, there is zero control or auditing. Anybody with the password can, apparently, see it all. But the trousers have been pulled up so the shit remains hidden.
Most physical guarding is a sham with "minimum wage SIA monkeys" doing the bare minimum. A facade.
re: Security guarding
One of my friends was a 'night watchman' for two years. He spent all his time reading the Financial Times, and now runs a business that owns at least three pubs.
Another story about physical guarding: BT has a lot of large old buildings that used to house the enormous Strowger telephone exchanges. Anyway, BT moved out of quite a few due to the economies of electronics, but robbers used to try to steal stuff from them (copper piping a favourite, whether connected to the mains water supply or not). So BT had lots of security guards who would try to chase the miscreants away, but often failed. So BT hired some retired Gurkha soldiers as guards. Their policy was to let the thieves enter, and when they were just about to start stealing something, creep up silently behind them and shout "BOO!" very loudly into their ear. Scared the shit out of them - they never came back.
Bouncers get bounced
It's amazing that this sort of thing still happens. More details please.. Was it some Access job in a public folder under a web site root or what? Or just the normal clear text username=admin, password = 123456789 thing. Or both?
as well as pictures of individuals suspected of offenses including shoplifting
Suspected, huh?
Suspected ?
And are the "suspected" aware that their photos have not only been retained by this outfit, but now leaked?
Many years ago I used to provide a service to disinfect virus-ridden computers.
My personal best for a single computer in a single company was just over 1,000 viruses.
At the offices of this company, when I discovered the state of it I told the computer's user (the MD's secretary) that it would take a while to get rid of all the viruses, and, as there would be a lot of waiting around for scans, it would be easiest if I took it back to my office to do it there. It wasn't usable as it was anyway. She said fine, so I took it and started work.
Some hours later an irate Managing Director was on the 'phone saying I must take the computer back to their offices immediately.
I took the lack of any explanation to mean that there was something on there that the MD didn't want me to see.
I took it back, still riddled with viruses, and I never heard from them again.
It's (still) a physical security company in Sutton-in-Ashfield, Nottinghamshire.
They still advertise "First Class Security...", which kinda sums it all up for me.
Struggling nowadays to find *anything* that isn't built on lies.
Luckily Britain's banks have been working hard for years to reduce bank robberies.
By closing all the branches.
Re: Luckily Britain's banks have been working hard for years to reduce bank robberies.
In yesterday's paper was a comment, about reducing the number of train which get cancelled - we'll remove them from the time table - so there are fewer trains - so the absolute number will decrease.
We did the bare minimum folks, yay us!
"We have acted accordingly and in line with our regulatory obligations."
Only now?
" I am investigating this with the supplier who developed and hosts the platform "
Yet another example of what I defined a couple of decades back as 'fire and forget management'. At least in the UK, the law actually requires the first party to take responsibility for third party data breaches, so it amazes me that said first parties never seem to check the security of their subcontractors' systems or activities until it's too late. How many businesses get their online offerings pen tested? Practically none in my experience.