Biometric data of a million users leaked

(Image credit: Shutterstock)

Security researchers have discovered a huge collection of unsecured biometric credentials and personal information including the fingerprint data of over one million people.

The discovery was made by researchers Noam Rotem and Ran Locar alongside vpnMentor and in addition to fingerprint data, they also found facial recognition information, unencrypted usernames and passwords as well as other personal information from users of Suprema's Biostar 2 security platform.

As with other recent data leaks, the information was found in a publicly accessible database which contained 27.8m records spanning 23GB of data. As of now, it is still unclear as to whether any malicious actors were able to access the data while it was publicly exposed.

Organizations around the world rely on the Biostar 2 security system to secure their commercial buildings. According to vpnMentor, the system is used to control access to facilities in the US, UK, Japan, India and the UAE.

Biostar 2

If cybercriminals did manage to access the data, they could use it to either create or modify existing user credentials which would allow them to access any building secured with Biostar 2.

Employees enrolled in the security system could also be at risk as their personal information could be used to commit identity fraud and their fingerprint data could be used to gain access to other systems that are secured using their unencrypted fingerprint data.

According to The Guardian, Suprema also recently announced that its Biostar 2 platform would be integrated into another security system called AEOS which is used in 83 countries by governments, banks and even the UK's Metropolitan Police service.

The security vulnerability has now been fixed but the biometric credentials and personal information exposed in the data leak could still be leveraged by malicious actors. Businesses using the Biostar 2 platform should change the passwords they use to access the system's dashboard immediately to prevent falling victim to any potential attacks.

Tripwire's VP of product management and strategy, Tim Erlin provided further insight on the data leak and the disadvantages of using biometric data for security purposes, saying:

“As an industry, we’ve learned a lot of lessons about how to securely store authentication data over the years. In many cases, we’re still learning and re-learning those lessons. Unfortunately, companies can’t send out a reset email for fingerprints. The benefit and disadvantage of biometric data is that it can’t be changed.

“Using multiple factors for authentication helps mitigate these kinds of breaches. As long as I can’t get access to a system or building with only one factor, then the compromise of my password, key card or fingerprint doesn’t result in compromise of the whole system. Of course, if these factors are stored or alterable from a single system, then there remains a single point of failure.”  

Via The Verge

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Data leak
Hacked Tata Technologies data leaked by ransomware gang
China
Chinese hackers targeting Juniper Networks routers, so patch now
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Avast cybersecurity
UK cybersecurity sector could be worth £13bn, research shows
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Latest in News
Samsung Galaxy Z Fold 6
The Samsung Galaxy Z Fold 7 could be in line for a Galaxy S25 Ultra-level camera upgrade
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Three iPhones on a green and blue background showing trails on Apple Maps
iOS 18.4 will give your iPhone a much-needed maps upgrade – but only if you're in the EU
A close up of Billy Bob Thornton's Tommy Norris in Paramount Plus' Landman TV series
The Taylor Sheridan supremacy lives on at Paramount+ as Landman gets renewed for season 2
Ryzen 9000 promotional material
AMD's most powerful processor ever actually runs better on Windows 10 than Windows 11
The logo and key art for Inzoi.
The newly revealed Inzoi system requirements are enough to make me go back to The Sims 4