ADVERTISEMENT

No password, no protection – Movistar security lapse leaves customers at risk

Movistar Costa Rica, a major telecommunications company, leaked hundreds of thousands of IDs, creating a potential goldmine for cybercriminals. However, the company states there is no evidence data was downloaded.

Movistar data leak

Image by Cybernews

Paulina Okunytė
Paulina Okunytė Senior Journalist
February 25, 2025 Updated: December 8, 2025 2 min read
Movistar leaked documents
  • Passports
  • Driver's licenses
  • Voters IDs
  • National identification card
  • Work permits
  • Selfies used in KYC

Customers at risk of financial losses

Movistar leaked documents
ADVERTISEMENT
Ernestas Naprys vilius Gintaras Radauskas Paulina Okunyte
Don’t miss our latest stories on Google News
Add us as your Preferred Source on Google.

To prevent similar data leaks, Cybernews suggests:

  • Adjusting access controls to disable public access, ensuring only authorized users and services can interact with the bucket
  • Regularly audit bucket permissions to confirm that only necessary roles and accounts have access to sensitive data. Implement Identity and Access Management (IAM) roles to enforce the principle of least privilege
  • Enable and routinely review Cloud Storage access logs to detect unauthorized access or suspicious activity. Utilize Google Cloud Logging to identify unusual access patterns
  • Verify that server-side encryption is enabled to safeguard stored data. While Google Cloud Storage encrypts data at rest by default, ensure the settings are properly configured
  • Manage encryption keys securely with Google Cloud’s Key Management Service (KMS), restricting access to authorized users only
  • Enforce HTTPS for all communications to ensure data remains secure while being transmitted between clients and the storage service
  • Conduct regular security audits, automate compliance checks with Google Cloud Security Command Center, and provide ongoing security training for employees
  • Configure alerts via Google Cloud Security Center or Stackdriver Monitoring to detect unusual access attempts or modifications to critical configurations in real time
  • Leak discovered:December 2nd, 2024
  • Initial disclosure: December 9th, 2024
  • Closed: February 18th, 2025
ADVERTISEMENT