FB pixel

Military dating site leaves database with 1M records exposed

Categories Access Control  |  Biometrics News
Military dating site leaves database with 1M records exposed
 

A dating and social networking platform focused on military members has left its database exposed, putting in danger more than 1.1 million records – including biometric data.

The unprotected database, belonging to Forces Penpals, was not password-protected nor encrypted and contained sensitive personally identifiable information (PII) of members of the U.S. and UK armed forces.

Forces Penpals describes itself as a site that allows users to support, chat, or date Army, Navy and Air Force personnel and veterans. Owned by Conduitor Limited, it was developed in 2002 as a way to boost the morale of armed forces sent to Iraq and Afghanistan, allowing civilians to write to members of the military. The site claims to have over 290,000 military and civilian users.

The unprotected data was found by cybersecurity researcher Jeremiah Fowler.

“Hypothetically, these documents could contain enough personal information to be a potential identity theft risk, allowing malicious actors to impersonate individuals for fraudulent activities or possible financial crimes,” Fowler writes for VPNMentor.

The exposed data could also potentially have national security implications. Earlier this month, Microsoft and U.S. authorities announced they uncovered that a hacking group tied to Russian intelligence has attempted to phish email accounts of former military and intelligence officials, Western think tank members and journalists.

Aside from user images, the database contained photos of potentially sensitive proof of service documents, which listed rank, branch of the service, dates, locations, and other information that should not be publicly accessible, according to Fowler. The database also had full names, mailing addresses, U.S. Social Security numbers, UK National Insurance Numbers and Service Numbers.

For now, it is unclear whether anyone else has gained access to the database. It is also uncertain whether the exposed data came from Forces Penpal’s dating app or its website and forum. The company says that the incident was due to a coding error and while the photos were public, the documents should not have been.

Serious data breaches have continued throughout 2024, including the massive National Public Data hack which exposed nearly 3 billion records containing personally identifiable information of U.S., Canadian and British citizens. At least four class action lawsuits have been filed against the Florida-based data broker.

Related Posts

Article Topics

 |   |   | 

Latest Biometrics News

 

EUDI What? As wallet deadline looms, awareness remains low

New consumer research from IDnow shows that only about half of French and German customers have heard of the European…

 

The surveillance networks cities do not have to buy

Private camera networks are beginning to emerge in cities across the U.S. which operate outside the boundaries of companies who…

 

German lawmakers approve live facial recognition use by federal police

Germany’s Federal Police appear on track to get new powers in a broad update of their governing rules, including a…

 

Kantara updates digital identity certification criteria for latest NIST revision

The Kantara Initiative has expanded its certification program for NIST’s Digital Identity Guidelines by releasing new criteria for their latest…

 

Ofcom launches investigation into TikTok over ‘age inference’ system

UK regulator Ofcom has opened an investigation to determine whether social media platform TikTok is in violation of the Online…

 

ROC sweeps Class B in NIST’s latent biometric accuracy assessment

ROC is making the case for U.S. domestic fingerprint biometrics at scale to be powered by algorithms developed in America,…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events