FedEx Legacy Server Exposes Customer Records
A legacy server of Bongo International, bought in 2014 by FedEx and shut down in 2017, exposed private information of thousands of customers. The password-less Amazon S3 server was discovered by researchers at the Kromtech Security Center.
The server contained more than 112,000 files dating from 2008 until September 2015. The service required filling out a U.S. Postal Service form as well as identification. The forms contained names, signatures, addresses and phone numbers. Among the identification documents were drivers’ licenses, voting cards, utility bills, resumes, medical insurance cards and even a few credit cards.
FedEx secured the server a few hours after ZDNet contacted FedEx. A FedEx spokesperson said that they “found no indication that any information has been misappropriated and will continue our investigation.”