Donation site for Ottawa "Freedom Convoy" exposed user data

Data Breach
(Image credit: Shutterstock)

People who donated to support the truckers currently participating in Canada's “Freedom Convoy” could have had their passport and driver licenses photos exposed due to a security lapse on the donation site GiveSendGo.

While the protest that began in January initially accepted donations using GoFundMe, the crowdsourcing giant decided to freeze around $7.9m in donations following police reports of violence and harassment in Ottawa.

As a result, the truckers behind the convoy decided to switch to the Boston-based donation service GiveSendGo as an alternative. According to the company, it processed over $4.5m in donations for the Freedom Convoy during its first day of hosting the “Adopt a Trucker” campaign.

In addition to this huge influx of donations, GiveSendGo also saw loads of malicious traffic to its site according to co-founder Jacob Wells who explained the situation further in a press release, saying:

“Along with the tremendous showing of support, there has also been plenty of push back. We’ve seen nearly 10 million bots trying to overwhelm our servers in just the past two hours. Though this has caused issues for the platform, we will not let it stand in the way of providing a safe and effective means of fundraising for our campaign owner across the globe.”

Exposed S3 bucket

As reported by TechCrunch, a person working in the security industry informed the news outlet that they had discovered the web address for an exposed Amazon S3 bucket while viewing the source code of the Freedom Convoy's page on GiveSendGo.

This exposed S3 bucket contained over 50GB of files including over a thousand pictures of passports and driver licenses collected from donors. These documents were likely submitted to GiveSendGo during the payments process as some financial institutions require this to be done before a payment can be processed.

After learning of the exposed S3 bucket and the personal information it contained, TechCrunch contacted Wells and it was secured a short time later. While it's not known how long the bucket was publicly accessible online, a text file left behind by a security researcher from September of 2018 warned that the bucket was “not properly configured”.

As countless businesses have left their databases unsecured and S3 buckets exposed online over the years, consumers can proactively protect their personal data online by investing in the best identity theft protection.

Via TechCrunch

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
A top online gift card store may have exposed private data on hundreds of thousands of users
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
This widely-used instant loan app leaks nearly 30 million files of user data
Stress
Time tracker tool spilled details on remote workers - millions of screenshots leaked
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras