Yet another data breach has grabbed international headlines, and this one involves the voting registration records of some 93.4 million Mexican citizens.
On April 14, Chris Vickery of MacKeeper discovered that he was able to access a tome of information, including names, birth dates, home addresses, ID numbers, and more, all on an unprotected Amazon cloud server. In a blog post, he noted that he immediately contacted both American and Mexican authorities (the U.S. State Department, the Department of Homeland Security, and the Mexican Embassy in Washington), whereupon the database was removed from the public domain eight days later on April 22.
In disclosing the enormous breach, Vickery wrote, “In my hands is something dangerous. It is proof that someone moved confidential government data out of Mexico and into the United States. It is a hard drive with 93.4 million downloaded voter registration records — The Mexican voter database.”
The database, the security expert says, “was configured purely for public access.” He adds that he has “no clue” as to why. “Under Mexican law, these files are ‘strictly confidential,’ carrying a penalty of up to 12 years in prison for anyone extracting this data from the government for personal gain.” Vickery blogged. And needless to say, this was a serious security meltdown.
“This is a significant breach, and what makes it worse is that the data was being held outside of Mexico,” Alex Cruz Farmer, vice president of cloud at security firm Nsfocus told IBTimes UK. He goes on to cite Mexico’s strict data governance rules that require data to be kept within Mexico. If it is exported for any reason, the data owner must have the authority of the data subject before the it can be exported.
Amazon Web Services has not yet commented directly on the records, but notes on its website: “While AWS manages security of the cloud, security in the cloud is the responsibility of the customer. Customers retain control of what security they choose to implement to protect their own content, platform, applications, systems and networks, no differently than they would for applications in an on-site datacenter.”
For its part, the Mexican government has expressed the seriousness of the offense. “The fact that this database is published to the public, it is not just a criminal offense, it is a national offense,” says Lorenzo Cordova Vianello, president of the Mexican National Electoral Institute. On Friday, the Institute said it filed a criminal lawsuit with Mexico’s Special Prosecutor’s Office for Electoral Crimes (FEPADE), and is also working with the country’s cyber police.
By Lulu Chang for Digital Trends
more recommended stories
Mexican journalist gunned down in Chiapas (VIDEO)
The public prosecutor’s office of Chiapas.
Mérida, recognized as one of the most important tourist spots in Southeast Mexico
The Municipal Tourism Directorate is currently.
Mérida Restaurant Week kicks off today!
From September 24 to 30, Mérida.
Mérida seeks to provide broader public space Internet connection
The technology management of the City.
The Cancun Declaration: 190 countries committed to preserve the environment
Among the commitments of 190 countries.
Immediate response by Yucatán’s law enforcement authorities as they capture Chicxulub murderers
The immediate and effective response by.
Tulum to become Mexico’s first sustainable tourism zone
The municipality of Tulum will become.
Yucatan the ultimate bird-watching destination
If you are into birdwatching, Yucatán.
Man drowns in Chuburná Puerto
A construction worker from the town.
Mexico strengthens leadership as an exporter of alcoholic beverages
Mexico Sep. 21 (Notimex).- Mexico strengthened.