Security

Don't panic, Chicago, but an AWS S3 config blunder exposed 1.8 million voter records

Personal info spills from another poorly secured Amazon service


A voting machine supplier for dozens of US states left records on 1.8 million Americans in public view for anyone to download – after misconfiguring its AWS-hosted storage.

ES&S says it was notified by UpGuard researcher Chris Vickery of the vulnerable database that contained personal information it collected from recent elections in Chicago, Illinois. The records included voters' names, addresses, dates of birth, and partial social security numbers. Some of the records also included drivers' licenses and state ID numbers.

"The backup files on the AWS server did not include any ballot information or vote totals and were not in any way connected to Chicago's voting or tabulation systems," ES&S said in a statement on Thursday.

"These back-up files had no impact on any voters' registration records and had no impact on the results of any election."

According to ES&S, it was alerted at 5.37pm on August 12 when, as part of a larger project to seek out sensitive data insecurely hosted on AWS, Vickery notified the company it had left its voter records out in the open. The cloud system was taken down four hours later. The biz, which supplies voting machines and backend services to more than 40 US states, is investigating the cockup.

A spokesperson for UpGuard confirmed to The Register that the vulnerable service was an AWS S3 silo accidentally set up to be open to the public. Strangely, only Chicago's data was exposed by a misconfiguration.

"We can't determine why the data exposed was only Chicago other than the bucket name, 'Chicagodb'. Our cyber risk team checked for other cities but came up empty," UpGuard's Kelly Rethmeyer told us.

Chicago's election board, meanwhile, says it is "deeply troubled" to hear of the exposure, but applauded ES&S for taking quick action.

"We have been in steady contact with ES&S to order and review the steps that must be taken, including the investigation of ES&S’s AWS server," said Chicago Election Board chairwoman Marisel Hernandez in a statement.

"We will continue reviewing our contract, policies and practices with ES&S. We are taking steps to make certain this can never happen again.”

This isn't the first time UpGuard found voter data sitting out in the open on AWS. Earlier this year the security firm caught a Republican analytics company who failed to put any access restrictions on an S3 instance that contained the personal details of nearly 200 million US voters within a 1.1TB database collected prior to the 2016 presidential election. ®

Send us news
16 Comments

Amazon to lure upstarts with $500K in AWS AI credits each

Come on in, drill into Anthropic and Mistral – that's not the sound of a door slamming shut behind you

GenAI will be bigger than the cloud or the internet, Amazon CEO hopes

And Andy Jassy will happily take your money along the way

Snowmobile, Amazon's truck-powered migration service, reaches the end of the road

Demand for bulk storage on wheels turned out to be wan

Amazon search results now less self-centered, boffin says

Self-preferencing pushback in Europe and US seems to have had some effect

Irish power crunch could be prompting AWS to ration compute resources

Users report being pointed to other EU regions if they need more grunt

US legislators propose American Privacy Rights Act - and it looks quite good

After two decades of calls for national protections, something may actually happen

Ex-Amazon exec claims she was asked to ignore copyright law in race to AI

High-flying AI scientist claims unfair dismissal following pregnancy leave

AWS severs connection with several hundred staff

'Necessary,' 'focusing our efforts,' 'deliver maximum impact' ... sounds just like all the other tech layoffs lately

AWS must pay $525M to cloud storage patent holder, says jury

Computing giant will appeal ruling, which found infringement was not 'willful'

Lawsuit accuses Grindr of illegally sharing users' HIV status

LGBTQ+ dating app's maker previously denied selling sensitive user data

96% of US hospital websites share visitor info with Meta, Google, data brokers

Could have been worse – last time researchers checked it was 98.6%

US-EAST-1 region is not the cloudy crock it's made out to be, claims AWS EC2 boss

It's the region where stuff gets stressed at scale first, says Dave Brown, as he plots variants of Amazon's Outposts