Apps & Consumer
Duales app exposed user IDs and passports on open server
A publicly accessible Amazon server owned by Duales potentially exposed hundreds of thousands of users' personal data, including government-issued documents, without a password.
A publicly accessible Amazon-hosted storage server owned by Canadian fintech company Duales left potentially hundreds of thousands of users’ personal data exposed without a password. The data, which included government-issued documents, was stored unencrypted on a staging site—a testing environment used by developers. Duales, which operates the money-transfer app Duc, resolved the data exposure on Tuesday after being alerted by TechCrunch. The app is used by customers to send money to other users, including overseas in Cuba and elsewhere, and has more than 100,000 user downloads on Google Play.
Anurag Sen, a security researcher at CyPeace, discovered the security lapse earlier in the week. Sen found that the Amazon-hosted storage server listed over 360,000 files containing government-issued documents and other information used by customers to verify their identity through “know your customer” (KYC) checks. These files included user-uploaded selfies to prove their real-world likeness, as well as driver’s licenses and passports. The exposed folders contained tens of thousands of user-uploaded files, which dated back to September 2020 and were being uploaded daily. The files also contained spreadsheets listing customer names, home addresses, and transaction details.
When contacted about the exposure, Duales chief executive Henry Martinez González stated that the data was stored on a staging site, but did not explain why the information was publicly accessible. Martinez González asserted that all protections were in place and noted that the company was notifying the appropriate parties. Following the alert, the files on the storage server were made inaccessible, though the app’s website briefly displayed a “bad gateway” error—indicating a server communication failure. The Office of the Privacy Commissioner of Canada, the country’s privacy regulator, has since reached out to the company. A spokesperson for the regulator confirmed that “The Office of the Privacy Commissioner of Canada has reached out to the company to obtain more information and determine next steps.”
This incident is the latest in a series of security lapses involving the exposure of sensitive identity data. Last year, the app TeaOnHer exposed thousands of its users’ passports and driver’s licenses, which were required for user verification. Similarly, Discord last year confirmed a data breach affecting around 70,000 government-issued documents uploaded by users for age verification. These incidents highlight the growing risks in Canada, Cuba, and the U.S. as consumer apps increasingly mandate identity verification without implementing sufficient data security measures.
Why it matters
The exposure of sensitive government-issued documents highlights ongoing security risks as apps increasingly require identity verification without sufficient data protection measures.