Health
[business][bleft]
Technology
[technology][bsummary]
Business
[business][twocolumns]
We are Dazlle. See our thoughts, stories and ideas.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Donec facilisis leo et bibendum pretium. Suspendisse ligula neque, ultrices nec interdum faucibus
Ad Code
Ad Code
Popular Posts

HOW CYBER CRIMINALS ABUSE CRYPTOCURRENCY EXCHANGES
January 25, 2023
NCA infiltrates cyber crime market with disguised DDoS sites
March 28, 2023
DATA BREACH: 1,000,000+ Financial Records Exposed in Data Incident Involving Fintech Company
Cybersecurity Journalist - Iain Fraser April 13, 2023
1,000,000+ Financial Records Exposed in Data Incident Involving Fintech Company
Syndicated By: Iain Fraser - Cybersecurity Journalist Gibraltar
Google Indexed on 130423 at 12:21 CET (Web & Hype Newsroom)
13 April 2023
Cybersecurity researcher Jeremiah Fowler discovered and reported to WebsitePlanet a non-password protected database that contained a large number of PDF documents.
The PDF documents that were made public included invoices from both individuals and businesses who used an app to pay for products and services. The invoices contained names, email addresses and physical addresses, phone numbers, and more. In addition, the documents also included notes about what the payment was for, the total amount, due date, and some even contained tax information such as a tax id number.
Upon further research, it was identified that the database belonged to NorthOne Bank, a financial technology company that is used by over 320,000 American businesses (based on information on their website). It is worth noting that NorthOne is not a full service bank. Banking services to NorthOne Bank are provided by The Bancorp Bank, which is also a member of the Federal Deposit Insurance Corporation (FDIC), a government agency that provides deposit insurance to financial institutions. NorthOne Bank has offices in New York, USA and Toronto, Canada and its services are available throughout North America.
I immediately sent a responsible disclosure notification to NorthOne Bank of the discovery of the possible security concern. Subsequently, I was informed by the bank that they had “investigated and had resolved the issue and that there were no outstanding open issues”. I first reported the finding on January 19th, 2023 and the database remained unsecured until January 31st, 2023, after sending several followup messages, restricting the access to the database and thus to the .PDF documents. It is unclear how long these records were exposed or who else may have had access to the database, if anyone did. We imply no claims or accusations about NorthOne Bank’s security practices. Details provided here are based on the response I received from the bank and our intention is solely to promote better security measures and responsible handling of potential vulnerabilities. It should also be noted that Bancorp Bank is not at fault or responsible for this breach.
The database allowed anyone with an internet connection and the database’s URL to see or download the .PDF documents. There were basic security controls preventing a full indexing of all documents. I estimated that there were over a million files in the database that were marked as “production”. In a random sampling of 1,000 invoices, I observed invoice amounts ranging from as low as $60 to over $10,000 for various services. These included home repairs, pet services, food and beverage, and even medical care. Learn More /...
About Jeremiah Fowler
Jeremiah Fowler is a Security Researcher and co-founder of Security Discovery. Jeremiah began his career in security research in 2015 and has a mission of data protection. He has helped identify and secure the data of millions of people around the world. His discoveries have been covered in Forbes, BBC, Gizmodo, among others. Security and responsible disclosure are not only a passion, but a way of protecting our digital lives. Learn More /...
Related posts
DATA BREACH: 1,000,000+ Financial Records Exposed in Data Incident Involving Fintech Company
Reviewed by Cybersecurity Journalist - Iain Fraser
on
April 13, 2023
Rating: 5

Subscribe to:
Post Comments (Atom)
Recent Posts
recentposts
Follow Us
[socialcounter]
[facebook][#][215K]
[twitter][#][115K]
[youtube][#][215,635]
[dribbble][#][14K]
[linkedin][#][556]
[google-plus][#][200K]
[instagram][#][152,500]
[rss][#][5124]
Popular
Labels
Comments
Recent
Socialize
Fashion
Music
News
Sports
Food
Technology
Insights 2
[tdfeatured][label=insights][layout=1]
Videos
Recipes By Category
Best Trending hot categories section with Latest Update
View The Recent Blog
Here you will find all of the most recent trending information.
Powered by Blogger.
Follow by Email
Get Notified About Next Update Direct to Your inbox* We promise that we don't spam !
Sports
4/block2/Sports
Post Top Ad
Responsive Ads Here
Search This Blog
Post Top Ad
Responsive Ads Here
Find Us On Facebook
Post Top Ad
Responsive Ads Here
Subscribe Us
#buttons=(Accept !) #days=(20)
Our website uses cookies to enhance your experience. Learn More
Accept !
Gadgets
5/col-left/Gadgets
Lifestyle
4/list1/Laptop
About
Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua Lorem ipsum dolor sit amet, consectetur adipisicing elit.
Our Company Inc. 1238 S . 123 St.Suite 25 Town City 3333 Phone: 123-456-789 Fax: 123-456-789
Featured Section
6/slider/recent
Videos
video/recent
What's New
block/recent
Product Services
Author Profile

Gibraltar based Professional Journalist, Accredited Authority Writer, Commentator and Corporate Lecturer on all aspects of AI, Geopolitics, Cybersecurity, Corporate Intelligence, OSINT & Crypto Awareness, Threat Management and Best Practice Compliance & Mitigation.
Voted Top 30 Cybersecurity News Websites Globally in 2023 for Information Security by Feedspot #CyberJourno #Scambaiter - Available for Assignments - Articles, Web Content, Guest Blogger
Gibraltar, Gibraltar, Gibraltar
Tags
Categories
Design by - Premium Blogger Templates | Distributed by Free Blogger Templates
Travel the world
Author Description
Hey there, We are Blossom Themes! We are trying to provide you the new way to look and use the blogger templates. Our designers are working hard and pushing the boundaries of possibilities to widen the horizon of the regular templates and provide high quality blogger templates to all hardworking bloggers!
Most Popular

HOW CYBER CRIMINALS ABUSE CRYPTOCURRENCY EXCHANGES
January 25, 2023
NCA infiltrates cyber crime market with disguised DDoS sites
March 28, 2023
Climb the mountains
Popular
Recent
recentposts
No comments: