Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Ecuador Data Leak Signposts A Clear Need For More Secure Public Clouds
Articles

Ecuador Data Leak Signposts A Clear Need For More Secure Public Clouds

Rich TurnerBy Rich TurnerSeptember 30, 2019Updated:December 30, 20215 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In the initial years of the public cloud, security was cited as the primary reason not to upload sensitive data or valuable workloads into public environments. It’s safe to say that situation has changed in recent years. In fact, 94 per cent of  global organisations use cloud services in some way, shape or form, according to our recent Global Advanced Threat Landscape Report. 

The public cloud is now regularly used to support digital transformation initiatives, including high-value data or important assets. For instance, nearly half of the 1000 global organisations surveyed in our report indicated that they are using SaaS-based business critical applications, and a similar percentage use the public cloud for regulated customer data.  

In fact, as demonstrated recently, the cloud is also used to store vast amounts of citizens’ data by public sector organisations. During a routine project earlier this month, internet security firm vpnMentor found that the personal data of almost all Ecuador’s approximately 17 million citizens – including 6.7 million children – was exposed on an unsecured server in Miami.

This data leak was made possible by a vulnerability on an unsecured AWS Elasticsearch server. Originally, It was believed that the Ecuadorian government had stored the data on this server itself, but it quickly emerged a few days that a local data analytics company called Novaestrat was responsible for the unsecured server, having left the data exposed in the public cloud without a password, allowing anyone to access the data stored on it.

Aside from the scale, this made front-page news due to the sheer breadth of exposed information. The exposed files contained official government ID numbers, phone numbers, family records, marriage dates, education histories and work records.

Notwithstanding whether they should have had the data or not, the most important lesson for those concerned with the ongoing security of client or citizen data held in the public cloud is that they must possess a clear understanding of who is responsible for securing what. 

If your organisation uses the public cloud, for example, do you understand the security controls your chosen cloud provider has in place? Is there clarity about what you may need to do to augment those policies and procedures?

Cloud security: a collective responsibility

Our research indicated that organisations are too heavily reliant on cloud vendors to secure critical data and assets. They must ensure credentials that allow access to these data and assets are as well protected in the cloud  as they are in an on-premises environment, particularly given some will be privileged in nature. With attackers specifically seeking to compromise high-value privileged credentials as the most effective way to achieve their goals, it is also concerning that so few organisations have a plan to protect them.

Many public cloud providers provide guidance on their shared responsibility models for security and compliance in cloud environments. This guidance typically outlines a shared responsibility model, in which the provider handles security up to a point and, beyond that, it becomes the responsibility of those using the service. The unfortunate reality, however, is that this guidance often gets ignored, or organisations are not aware of it, and leave cloud security solely to their cloud provider.

In fact, our research indicates that the key benefit that the organisations hope to see from their usage of cloud is the ability to –offload security to the cloud vendor, either completely or in part. Cloud vendors rightly take responsibility for certain aspects of security when companies use their services, but they are very clear about where their clients must step in and assume accountability. Protecting customer data remains the responsibility of the client, and businesses must take note of their responsibility. Right now, three quarters entrust the security of their cloud workloads completely to their cloud vendor, while half this number realise that this will not provide them with broad protection, but continue to do it anyway. It’s abundantly clear, therefore, that the shared security responsibility model is either not well-understood or is being ignored by many organisations. 

Don’t pass on privilege

If this wasn’t concerning enough, there is also a widespread lack of awareness about the existence of privileged accounts, secrets and credentials in IaaS and PaaS environments, which is exacerbated by the lack of an appropriate strategy to secure them: Less than half  have a privileged security plan for the cloud, according to our study, indicating that they could be placing themselves – and their customers’ data – at significant risk.

Ecuador isn’t the only government to inadvertently expose its citizens’ data through an unsecured cloud server, and in all likelihood probably won’t be the last. A similar Elasticsearch server was found to have exposed the voter records of approximately 14.3 million people in Chile – around 80% of its population – earlier this year

As public sector organisations and government departments increasingly look to the cloud to help them become more agile and better serve their citizens, it’s vital they continue to evolve their cloud security strategies to proactively protect against emerging threats, and reinforce trust among the citizens who rely on their services.

Rich Turner

SVP EMEA

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    Tenable warns AI adoption is outpacing governance as cloud exposure risks surge

    May 15, 20264 Mins Read

    Cloud Security Controls Explained: A Definitive Guide

    March 19, 20269 Mins Read

    The Real Cost of Inconsistent Third-Party Access

    December 18, 20255 Mins Read
    ISB-Bora-Side-Bar

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}