In some cases, this included their check-in time and room number.

It affected1,000s of people across the globe,with millions of new records being added daily.

This represented amassive breach of security for the governmentagencies and departments impacted.

Report: Travel Reservations Platform Leaks US Government Personnel Data

But rare are these times.

Most often, we need days of investigation before we understand whats at stake or whos leaking the data.

We need to be thorough andmake sure everything we find is correct and true.

Article image

We work hard on publishingaccurate and trustworthy reports,to ensure everybody who reads them understands their seriousness.

For this reason, the database our team found was connected to myriad hotel and travel platforms.

All this information isincredibly valuable for criminal hackersand online thieves.

Article image

For the US government, alarm bells should be ringing.

We also found their email address, phone numbers, and other sensitive personal data.

This represents amajor flaw in the data security apparatusaround such sensitive information.

Article image

Criminals could pose as hotels or booking engines used by guests,crafting convincing emails to easily fool them.

The effects could be devastating, both financially and personally.

They could use this information toplan home burglaries with minimal riskof being caught or target them abroad.

Article image

Furthermore, with hotel room numbers exposed, guests could be also targeted while on holiday.

The scope for potential criminal activity is huge.

This gives invaluableinsight into the operations and activities of the US government and military personnel.

Article image

The national security implications for the US government and military are wide-ranging and serious.

Compromising your customers personal data cancreate major reputational damage and trust issues in the future.

They thoroughly inspect each discovered gap for potential data leakage.

If possible, we will also alert those affected by the breach.

Whoever owns the database in questionuses an Elasticsearch database,which is ordinarily not designed for URL use.

The purpose of this web mapping project is to helpmake the internet safer for all users.

[Publication date: 21.10.2019]

like, comment on how to improve this article.