Yet another data breach has grabbed international headlines, and this one involves the voting registration records of some 93.4 million Mexican citizens.
On April 14, Chris Vickery of MacKeeper discovered that he was able to access a tome of information, including names, birth dates, home addresses, ID numbers, and more, all on an unprotected Amazon cloud server. In a blog post, he noted that he immediately contacted both American and Mexican authorities (the U.S. State Department, the Department of Homeland Security, and the Mexican Embassy in Washington), whereupon the database was removed from the public domain eight days later on April 22.
In disclosing the enormous breach, Vickery wrote, “In my hands is something dangerous. It is proof that someone moved confidential government data out of Mexico and into the United States. It is a hard drive with 93.4 million downloaded voter registration records — The Mexican voter database.”
The database, the security expert says, “was configured purely for public access.” He adds that he has “no clue” as to why. “Under Mexican law, these files are ‘strictly confidential,’ carrying a penalty of up to 12 years in prison for anyone extracting this data from the government for personal gain.” Vickery blogged. And needless to say, this was a serious security meltdown.
“This is a significant breach, and what makes it worse is that the data was being held outside of Mexico,” Alex Cruz Farmer, vice president of cloud at security firm Nsfocus told IBTimes UK. He goes on to cite Mexico’s strict data governance rules that require data to be kept within Mexico. If it is exported for any reason, the data owner must have the authority of the data subject before the it can be exported.
Amazon Web Services has not yet commented directly on the records, but notes on its website: “While AWS manages security of the cloud, security in the cloud is the responsibility of the customer. Customers retain control of what security they choose to implement to protect their own content, platform, applications, systems and networks, no differently than they would for applications in an on-site datacenter.”
For its part, the Mexican government has expressed the seriousness of the offense. “The fact that this database is published to the public, it is not just a criminal offense, it is a national offense,” says Lorenzo Cordova Vianello, president of the Mexican National Electoral Institute. On Friday, the Institute said it filed a criminal lawsuit with Mexico’s Special Prosecutor’s Office for Electoral Crimes (FEPADE), and is also working with the country’s cyber police.
By Lulu Chang for Digital Trends
more recommended stories
Zapatista rebels reject meeting with López Obrador
Mexico’s leftist President-elect Andres Manuel Lopez.
Municipal crews work 24/7 to keep sargassum off the beach in Cancun
“The cleaning works carried out since.
Yucatecan enterpreneurs seek to strengthen local productivity with “Tech Day”
In order to strengthen partnerships, and.
Catalog highlights relevance of the flower in Mexican Culture
The flower, addressed as a substantive.
19th edition of the International Jazz Festival of Campeche features world-class artists
Campeche will present its International Jazz.
PEMEX pipeline on the Mérida-Progreso highway explodes as fuel was being illegaly extracted
According to unofficial reports, the explosion.
Measures against Influenza reinforced by Isstey authorities
Mérida, Yucatán, July 18, 2018.- In.
Oscar winning Guillermo Del Toro grants scholarships to three Mexican talents in animation
Filmmaker Guillermo del Toro, with the.
Mexican congress asks Health Secretariat to evaluate if there is an Influenza epidemic in Yucatan
The Mexican Congress directed an appeal.
AMLO’s government would consider legalization of drugs
Mexico’s new government is set to explore the.