Wednesday , January 22 2025
mc2

Background info of one-third of the US population is now public

Cybernews has uncovered a huge data leak at MC2 Data, a background check company, impacting many US citizens. MC2 Data and similar companies provide public records and background check services by collecting and analyzing data from various public sources, such as criminal records, employment history, family information, and contact details.

They use this information to create comprehensive profiles that employers, landlords, and others rely on for decision-making and risk management.

Delay patching leaves about 50,000 Fortinet firewalls to zero-day attack

Fortinet customers must apply the latest updates, as almost 50,000 management interfaces remain vulnerable to the latest zero-day exploit. The...
Read More
Delay patching leaves about 50,000 Fortinet firewalls to zero-day attack

Daily Security Update Dated: 21.01.2025

Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data breaches, website defacement and so...
Read More
Daily Security Update Dated: 21.01.2025

126 Linux kernel Vulns Allow Attackers Exploit 78 Linux Sub-Systems

Ubuntu 22.04 LTS users are advised to update their systems right away due to a crucial security patch from Canonical...
Read More
126 Linux kernel Vulns Allow Attackers Exploit 78 Linux Sub-Systems

CERT-UA alerts about “security audit” requests through AnyDesk

Attackers are pretending to be Ukraine's Computer Emergency Response Team (CERT-UA) using AnyDesk to access target computers. “Unidentified individuals are...
Read More
CERT-UA alerts about “security audit” requests through AnyDesk

Oracle Critical Pre-Release update addressed 320 flaw

Oracle Critical Patch Update Pre-Release Announcement shares details about the upcoming update scheduled for January 21, 2025. Note that this...
Read More
Oracle Critical Pre-Release update addressed 320 flaw

OWASP Reveils Top 10 Smart Contract Vulnerabilities for 2025

OWASP has released its updated list of the top 10 vulnerabilities in smart contracts for 2025. This guide highlights the...
Read More
OWASP Reveils Top 10 Smart Contract Vulnerabilities for 2025

Multiple Azure DevOps Vulns Allow To Inject CRLF Queries & Rebind DNS

Security researchers have found several vulnerabilities in Azure DevOps that could enable attackers to inject CRLF queries and carry out...
Read More
Multiple Azure DevOps Vulns Allow To Inject CRLF Queries & Rebind DNS

Intel holds 22 employees from one Bangladeshi University

Intel Corporation is a leading semiconductor chip manufacturer, employing at least 22 graduates from the Department of Applied Chemistry and...
Read More
Intel holds 22 employees from one Bangladeshi University

VPN Surge 1500% in USA after TikTok Shut Down

vpnMentor’s Research Team is monitoring the potential TikTok ban in the U.S., driven by national security and data privacy issues....
Read More
VPN Surge 1500% in USA after TikTok Shut Down

MITRE Launches D3FEND 1.0; The Milestone for Cybersecurity Ontology

MITRE launched D3FENDTM 1.0, a cybersecurity framework that provides a vocabulary and understanding of the cyber domain. D3FEND 1.0, funded...
Read More
MITRE Launches D3FEND 1.0; The Milestone for Cybersecurity Ontology

Websites that MC2 Data operates include:

PrivateRecords.net
PrivateReports
PeopleSearcher
ThePeopleSearchers
PeopleSearchUSA
mc2 data leak

Source: Cybernews

A recent Cybernews study found that a company exposed a database containing 2.2TB of sensitive data, leaving it unprotected and accessible online.

A human error likely exposed over 106 million records with private information about US citizens, affecting at least 100 million individuals and raising serious privacy and safety concerns.

The data of 2,319,873 users from MC2 Data services was leaked, compromising those requiring background checks.

Leaked data included:

Names
Emails
IP addresses
User agents
Encrypted passwords
Partial payment information
Home addresses
Dates of birth
Phone numbers
Property records
Legal records
Property records
Family, relatives, neighbors data
Employment history

Putting countless individuals at risk:

Businesses offering public records and background check services must follow strict regulations at the federal, state, and local levels to ensure legal operations and protect individuals’ data.

The leak found by the Cybernews team raises serious concerns about how organizations handle sensitive data. The exposure of a significant amount of personally identifiable information (PII) compromises privacy and increases the risk of identity theft. Additionally, MC2 Data could face reputational harm and legal consequences.

“Background-checking services have always been problematic, as cybercriminals would often be able to purchase their services to gather data on their victims,” said Aras Nazarovas, a Cybernews security researcher.

“While background-check services keep trying to prevent such cases, they haven’t been able to stop such use of their services completely. Such a leak is a goldmine for cybercriminals as it eases access and reduces risk for them, allowing them to misuse these detailed reports more effectively.”

According to Cybernews researchers, the leaked subscribers’ information is also troublesome, as they could be high-value targets for cybercriminals. These subscribers could be employers, landlords, law enforcement, and similar entities.

“If anyone else accessed this information, it could spark conflicts in some communities and organizations,” adds the researcher. Cybernews contacted MC2 Data for a comment but has not yet received a response.

Source: Cybernews

Check Also

Canadian company exposed unprotected almost 5 million records

Cybersecurity expert, Jeremiah Fowler discovered an unsecured database containing almost 5 million records reportedly relating …

Leave a Reply

Your email address will not be published. Required fields are marked *