Discovery of Unstable Databases Containing Sensitive Information on Illinois Voter’s Personnel and Social Security Numbers
There are 4.5 million voter records in Illinois which can be found on the internet, and they include driver’s license numbers, full and partial Social Security Numbers, and documents like death certificates. Longtime security researcher Jeremiah Fowler stumbled upon one of the databases that appeared to contain information from DeKalb County, Illinois, and subsequently discovered another 12 exposed databases. None were password protected nor required any type of authentication to access.
A security researcher this week disclosed the discovery of more than a dozen unsecured databases containing sensitive information on voters in counties across Illinois. The data, which was stored by a government contractor, includes driver’s license numbers, Social Security numbers, death certificates, and more. The episode shows how difficult it can be to protect all voter data at the same time.
The state of Illinois is required to be notified of the data breach within 45 days. A standard version of a Champaign County contract for technology services posted publicly through a Freedom of Information Act request requires a contractor to notify the impacted county within 15 minutes of identifying a data breach.
An investigation of a communications breach by Platinum Technology Resource and its connection with a state-of-the-art voter registration server in Illinois (via WIRED)
The notification was viewed by WIRED on Friday. Platinum claimed that the files containing voter registration documents may have been scanned, but that did not mean a deeper compromise of its systems. “There was a thorough investigation executed. The findings support our ongoing belief there is no evidence of voter registration forms being leaked or stolen … New and additional safeguards were deployed around voter registration documents.
Fowler reported the unprotected databases to Platinum on July 18, but he says he didn’t receive a response and the databases remained exposed. As he began to dig into public records, he discovered Platinum works with a managed services provider in Illinois and he sent a disclosure to that company as well on July 19. Again, he says he did not receive a response, but shortly after the databases were secured, pulling them from public view. Platinum and Magenium did not return WIRED’s multiple requests for comment.
Through public records, Fowler determined that all of the counties appear to contract with an Illinois-based election management service called Platinum Technology Resource, which provides voter registration software and other digital tools along with services like ballot printing. DeKalb, one of the Illinois counties that use Platinum Technology Resource as an election services provider, confirmed to WIRED that it had a relationship with Platinum.
Threats to critical infrastructure loom as hacking becomes more sophisticated and aggressive. The biggest vulnerabilities aren’t from software issues, but from mistakes that leave the safe door open and expose crown jewels. In the years after efforts to shore up election security across the United States, state and local awareness of cyber issues has improved much. But as this year’s US election quickly approaches, the findings reflect the reality that there are always more oversights to catch.
If it seems like there’s suddenly a whole lot more data breaches, you may be right. Part of this apparent spike is thanks to the growing popularity of infostealer malware. These malicious software are being used to gain access to as many sensitive data as possible. Criminal hacker forums contain stolen data that can be used to break into victims’ accounts, which can include large corporations. It is a good reminder to always enable multi-factor authorisation wherever you are.
Big Security and Privacy News We Covered in WIRED’s First Reporter on Russia Cybercriminals in WSJ Reporter Prisoner Swap
The FBI has a long and sordid history of confidential instuments. A WIRED investigation that was published this week shows how a person who was in contact with far- right groups ended up giving information to the Feds, which they used to encourage violent extremists online.
Hacking computers with lasers has always been a rich person’s game—until now. Two security researchers have created a tool that can be produced for $500, a tiny amount of the cost of laser equipment traditionally used for hardware hacking. The pair will be detailing the RayV Lite at the Black Hat security conference next week in Las Vegas. We’re going to be at Black Hat and the other big security conference in Las Vegas next week, so please check back for more coverage on Tuesday.
But that’s not all. Each week, we round up the big security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.
Source: US Hands Over Russian Cybercriminals in WSJ Reporter Prisoner Swap
A Wall Street Journal Reporter Prisoner Swap: The US Hands Over Russian Cybercriminals in a Crime-To-Deep Prisoner Exchange
In a historic prisoner swap between the US and Russia, Wall Street Journal reporter Evan Gershkovich and former Marine Paul Whelan were freed from Russian detention on Thursday. A secret deal involving 24 prisoners, two of which were criminals, was negotiated by the White House for over a year. NBC News reports this is likely the first time the US has released international hackers in a prisoner exchange.
The two Russian hackers are Roman Seleznev and Vladislav Klyushin. Seleznev was given 27 years in prison for his racketeering convictions. The US Department of Justice says he installed computer code on point-of-sale systems software which allowed him to steal millions of credit card numbers. The US prosecutors described the $93 million hack- to-trade conspiracy as a nine-year prison sentence for Klyushin.
Meta, the parent company of Facebook and Instagram, will pay $1.4 billion to settle a lawsuit brought by the Texas attorney general, whose office accused the social media behemoth of illegally capturing the biometric data of millions of Texans. Meta was sued by the state in 2000 after they implemented a feature that automatically suggested people to tag in photos and videos uploaded to Facebook. Texas law makes it illegal for companies to capture and profit from someone’s fingerprints without their consent. While Meta did not admit to any wrongdoing as part of the agreement, according to Texas attorney general Ken Paxton’s office, it’s the single largest privacy settlement ever obtained by a state.
Source: US Hands Over Russian Cybercriminals in WSJ Reporter Prisoner Swap
Microsoft Azure vs. Microsoft, a cyberattack caused by a large number of users globally, has been described as a distributed denial of service
The tech company said on Wednesday that a cyberattack caused a widespread Microsoft Azure outage that impacted a range of services. According to Microsoft’s Azure status history page, the incident lasted approximately eight hours on Tuesday and affected “a subset” of customers globally.
The company described the attack as a distributed denial of service, a malicious attempt by hackers to disrupt a target company’s operations by overwhelming its infrastructure with a flood of internet traffic. According to PCMag, two hacktivist groups have claimed responsibility. Microsoft will review the incident.


