Security lapse in hotel check-in system exposed over a million customer identity documents
A major security lapse in Tabiq, a hotel check-in system maintained by Japanese startup Reqrea, exposed more than one million passports, driver’s licenses, and selfie verification photos to the open web. The exposure occurred because one of the system’s Amazon cloud storage buckets was set to public access, allowing anyone with the bucket name to view sensitive documents through a web browser without a password. Independent security researcher Anurag Sen discovered the issue and alerted TechCrunch, which in turn contacted Reqrea and Japan’s cybersecurity coordination team, JPCERT. The company subsequently secured the bucket and began reviewing the extent of the exposure. The exposed documents date back to early 2020 and include information from hotel guests worldwide. While it remains unclear if any unauthorized parties accessed the data prior to the fix, the incident highlights recurring issues with companies failing to follow basic cybersecurity practices. Such lapses are increasingly significant as age-verification laws and identity checks become more common, placing individuals at greater risk of identity fraud. Reqrea has pledged to notify affected individuals after completing its investigation.
