FB pixel

Event access ID verification app exposes biometrics, PII

Event access ID verification app exposes biometrics, PII
 

A trove of files used by an identity verification, including selfies used for face biometrics, was exposed by a vulnerability in the FacePass app, and then fixed after researchers notified the developer.

FacePass is widely used in Brazil, according to the report, which is why the 1.6 million files contained numerous Brazilian national IDs and taxpayer registry (CFP) numbers. Selfies, full names, phone numbers and the company’s system credentials were also exposed. Cybernews reports its research team found the files in an AWS S3 bucket.

The names and IDs were found together in Excel files, which makes them easier to commit fraud or carry out tailored phishing schemes with, and to sell on the dark web, Cybernews points out.

“This trove of exposed data places users at significant risk of identity theft, financial fraud, and targeted phishing attacks. Cybercriminals could leverage national IDs and selfies to bypass biometric verification systems, impersonate victims, or gain unauthorized access to financial accounts,” Cybernews researchers said.

If the data had been stored in separate locations or the selfies deleted after a reference template was created, the potential damage would have been significantly reduced.

The AWS credentials found could also be used to access company systems and then extract, change or delete user data.

FacePass is mostly used in Brazil for purchasing tickets and attending events, a use case for biometrics which gained major market growth in 2024, setting up even more rollouts this year.

The leak was discovered and the disclosure process initiated on January 30, and the vulnerability was closed on February 19.

Related Posts

Article Topics

 |   |   |   |   |   |   |   | 

Latest Biometrics News

 

ICE using data and probability to decide where to detain and arrest people

U.S. Immigration and Customs Enforcement’s Enhanced Leads Identification & Targeting for Enforcement (ELITE) tool is being used to identify “targets”…

 

In AI era, identity is about governance, Microblink’s Hartley Thompson tells BU Podcast

“One of the defining things in my life is change,” says Hartley Thompson of Microblink. “How do you react to…

 

CLR Labs wins funding to support biometrics, IAD, digital wallet standardization

Cabinet Louis Reynaud (CLR Labs) has won funding from a French government program to support its standardization efforts in biometrics,…

 

Checkr crossed $800M gross in 2025 as biometric background checks expand

Biometric background check provider Checkr is celebrating 2025 as its most successful year ever, with gross revenue surpassing $800 million…

 

Identity and risk infrastructure startup secures $12M for Europe, LATAM expansion

Monnai, which provides identity and risk data infrastructure, has announced a 12 million dollar equity funding round led by Motive…

 

Hopae appoints Sarah Clark to lead US expansion of digital ID verification platform

Sarah Clark is Hopae’s new CPO and GM for North America, joining the Seoul-headquartered company to help extend the reach…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events