Duc's exposed server left customer IDs open to the web.

A significant data breach involving the money transfer app Duc has exposed sensitive customer information, including thousands of driver’s licenses and passports, to the open web.

3 min readTechCrunch
Duc's exposed server left customer IDs open to the web.

An exposed Amazon-hosted server left customer IDs open to the web, and that is a failure we should all take seriously. This is not a minor oversight or a technical hiccup; it is a reminder that convenience often outpaces security in the tools we rely on daily. When a server is left unprotected, it is not just a company's problem. It becomes a personal vulnerability for every person whose information was left exposed.

For you, the practical takeaway is straightforward: your data is only as safe as the weakest link in the chain. In this case, customer IDs were accessible to anyone who knew where to look, no password required. That means the barrier to entry for misuse was essentially zero. While we do not know the full scope of what was accessed or who might have stumbled upon it, the fact that this information was sitting in an open digital drawer is enough to warrant caution. If you have interacted with this platform, you should assume your information may have been exposed and act accordingly.

What this reveals is a broader truth about the current state of data management. Many tools promise innovation and efficiency, but they often inherit the same blind spots as the legacy systems they aim to replace. The rush to build and scale can overshadow the fundamentals of security, especially when the focus is on user experience or feature rollouts. This is not about casting blame on any single individual or team. It is about recognizing that security is not a one-time checkbox; it is an ongoing discipline that must be embedded into how systems are designed and maintained.

The practical question for you is not whether to abandon digital tools altogether, but how to hold them accountable. Ask the companies you trust about their security practices. Look for transparency in how they handle breaches, not just in how they market their product. Demand that they treat your data as a responsibility, not a byproduct of their service. In the meantime, take stock of what you share and where. Change passwords, enable two-factor authentication, and monitor for any unusual activity. These steps are not paranoid; they are practical responses to a real and present risk. The lesson here is not to fear technology, but to approach it with open eyes and a healthy sense of skepticism.

From TechCrunch

An exposed Amazon-hosted server allowed anyone to access reams of customer data without needing a password.

Read the original at TechCrunch