Monday, August 3, 2026

Compute & Cloud

Reqrea hotel check-in system leaks over 1 million user documents

A misconfigured Amazon storage bucket by Japan-based Reqrea exposed more than 1 million customer identity documents, though it remains unclear if unauthorized parties accessed the data.

Reqrea hotel check-in system leaks over 1 million user documents
Photo: Reqrea

A hotel check-in system called Tabiq, operated by the Japan-based tech startup Reqrea, exposed more than 1 million customer passports, driver’s licenses, and selfie verification photos. The exposure occurred because the startup set one of its Amazon cloud-hosted storage containers—the storage buckets used to store customer data—to be publicly accessible. The data is now offline after TechCrunch alerted the company responsible.

Independent security researcher Anurag Sen discovered that the system was leaking the sensitive documents and contacted TechCrunch to help notify the company. The exposed files, which date back to early 2020 up to as recently as this month, included identity documents of visitors from countries around the world. Details of the exposed bucket were also captured by GrayHatWarfare, a searchable database that indexes publicly visible cloud storage. Reqrea locked down the storage container after TechCrunch reached out to both the startup and Japan’s cybersecurity coordination team, JPCERT.

Reqrea stated that it does not know how the storage bucket became public. In an email acknowledging the exposure, Reqrea director Masataka Hashimoto said, “We are conducting a thorough review with the support of external legal counsel and other advisors to determine the full scope of exposure.” Hashimoto added that the company plans to notify affected individuals once it has completed its investigation. However, it remains unclear whether anyone other than Sen accessed the exposed data before it was secured. Hashimoto noted that the company is reviewing its logs to determine if there had been any unauthorized access prior to securing the bucket.

The incident represents a significant security lapse for Tabiq, which relies on facial recognition and document scanning to check guests in. This hotel check-in system lapse follows other recent incidents involving sensitive government-issued documents. Earlier this year, TechCrunch reported on the exposure of identity documents uploaded by customers of the money transfer service Duc App. Additionally, a data breach at car rental service Hertz last year saw hackers make off with driver’s license information belonging to at least 100,000 customers. These incidents highlight the ongoing risks associated with identity verification checks, commonly known as “know your customer” processes, which require users to upload highly sensitive personal documents to third-party systems.

Why it matters

This incident highlights how basic cybersecurity failures—rather than sophisticated attacks—continue to expose sensitive personal data, a growing risk as businesses around the world increasingly rely on digital identity verification.