{"id":2314,"date":"2018-02-07T10:13:43","date_gmt":"2018-02-07T14:13:43","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=2314"},"modified":"2018-02-07T10:13:43","modified_gmt":"2018-02-07T14:13:43","slug":"amazon-web-services-bucket-leaks-12000-social-media-influencers-data","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/","title":{"rendered":"Amazon Web Services Bucket Leaks 12,000 Social Media Influencers&#8217; Data"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2315\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/02\/cyberselfie-mod.jpg\" alt=\"social media influencers data exposed octoly\" width=\"800\" height=\"400\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/02\/cyberselfie-mod.jpg 800w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/02\/cyberselfie-mod-300x150.jpg 300w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/02\/cyberselfie-mod-768x384.jpg 768w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/02\/cyberselfie-mod-540x270-2.jpg 540w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/02\/cyberselfie-mod-162x81-1.jpg 162w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/02\/cyberselfie-mod-360x180.jpg 360w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Upguard researcher Chris Vickery announced the discovery of an unsecured Amazon Web Services S3 cloud storage \u201cbucket\u201d from Parisian brand marketing company Octoly. The bucket left Octoly\u2019s enterprise IT operations and the personal data of 12,000 social media influencers\u2014Instagram, Twitter and Youtube content contributors\u2014completely exposed.<\/span><\/p>\n<br \/>Widget not in any sidebars<br \/>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The data leak exposed the inner working of Octoly\u2019s digital brand marketing operations in North America and Europe, client info including information on L\u2019Oreal and Blizzard Entertainment, and specially commissioned analytics information that could prove damaging to their business operations. Most disturbingly, the data included the real names, addresses, phone numbers, birthdates, emails (including emails used for transaction sites like PayPal), and hashed user credentials of Octoly\u2019 social media influencers. These individuals, mostly young women, receive free beauty products, merchandise, and gaming content to review and promote on their personal accounts, providing free exposure and organic marketing to younger audiences. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">According to an <\/span><a href=\"https:\/\/www.upguard.com\/breaches\/cloud-leak-octoly\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400\">Upguard blog post<\/span><\/a><span style=\"font-weight: 400\"> by Vickery, the bucket was exposed due to an \u201cerroneous configuration of the repository for public access,\u201d and was discovered on January 4. Vickery sent repeated warnings to Octoly about the exposed data, who eventually did delete some of the information from the bucket. However, they left the spreadsheets with their social media influencers\u2019 personal data unsecured until February 1. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">According to the Vickery\u2019s post, \u201cOctoly\u2019s incident response, from the highest corporate levels, did not properly account for the significance of the exposed data. The corporation\u2019s deletion of one backup file, while failing to secure the S3 bucket or remove any of the large amount of other damaging data still exposed, left a large amount of personally identifiable information exposed weeks after Octoly assured the UpGuard Cyber Risk Team that the breach had been closed.\u201d <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Vickery added separately that the social media credentials were hashed but could easily be cracked by dedicated hackers with enough time, which leaves thousands of people vulnerable to identity theft and password reuse attacks. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Octoly\u2019s social media influencers have publicly expressed frustration at Octoly\u2019s slow and insufficient incident response, which left them in the dark about the possible exposure until recently. On Twitter, Octoly apologized and stated that there were \u201cno signs\u201d that any personal information had been downloaded or used maliciously. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Vickery has expressed doubt on this claim, as he believes it is more likely the Octoly has no idea if anyone accessed it. His blog point notes that the social media personalities may face <\/span><a href=\"https:\/\/www.pewinternet.org\/2014\/10\/22\/part-5-witnessing-harassment-online\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400\">harassment<\/span><\/a><span style=\"font-weight: 400\"> both online and in real life with their personal information exposed. Many of them, particular female users, prefer to stay anonymous or operate under their first name only in online interactions to avoid such harassment. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The entire incident speaks to the PR nightmare a data leak can bring, particular one with an ineffective <a href=\"https:\/\/solutionsreview.com\/endpoint-security\/safeguard-enterprise-incident-response-plan-irp\/\" target=\"_blank\" rel=\"noopener\">incident response plan<\/a>. It also highlights the issues surrounding the collection of personal information and credentials, and the distrust consumers experience <a href=\"https:\/\/solutionsreview.com\/identity-management\/numbers-gdpr-data-management\/\" target=\"_blank\" rel=\"noopener\">sharing their personal data and passwords<\/a> with corporations. \u00a0\u00a0<\/span><\/p>\n<br \/>Widget not in any sidebars<br \/>\n","protected":false},"excerpt":{"rendered":"<p>Upguard researcher Chris Vickery announced the discovery of an unsecured Amazon Web Services S3 cloud storage \u201cbucket\u201d from Parisian brand marketing company Octoly. The bucket left Octoly\u2019s enterprise IT operations and the personal data of 12,000 social media influencers\u2014Instagram, Twitter and Youtube content contributors\u2014completely exposed. The data leak exposed the inner working of Octoly\u2019s digital [&hellip;]<\/p>\n","protected":false},"author":41,"featured_media":2315,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[6,1],"tags":[142,617,16,112,71,244,70,616,91,245],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Octoly AWS Bucket Leaks 12,000 Social Media Influencers&#039; Data<\/title>\n<meta name=\"description\" content=\"Upguard researcher announced the discovery of an unsecured AWS S3 cloud storage \u201cbucket\u201d from Octoly exposing 12,000 social media influencers&#039; data.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Canner\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/\",\"name\":\"Octoly AWS Bucket Leaks 12,000 Social Media Influencers' Data\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/02\/cyberselfie-mod.jpg\",\"datePublished\":\"2018-02-07T14:13:43+00:00\",\"dateModified\":\"2018-02-07T14:13:43+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\"},\"description\":\"Upguard researcher announced the discovery of an unsecured AWS S3 cloud storage \u201cbucket\u201d from Octoly exposing 12,000 social media influencers' data.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/02\/cyberselfie-mod.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/02\/cyberselfie-mod.jpg\",\"width\":800,\"height\":400,\"caption\":\"Will Facebook Force the Creation of a U.S. National Privacy Law?\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Amazon Web Services Bucket Leaks 12,000 Social Media Influencers&#8217; Data\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services\",\"description\":\"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\",\"name\":\"Ben Canner\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"caption\":\"Ben Canner\"},\"description\":\"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/bcanner\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Octoly AWS Bucket Leaks 12,000 Social Media Influencers' Data","description":"Upguard researcher announced the discovery of an unsecured AWS S3 cloud storage \u201cbucket\u201d from Octoly exposing 12,000 social media influencers' data.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/","twitter_misc":{"Written by":"Ben Canner","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/","url":"https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/","name":"Octoly AWS Bucket Leaks 12,000 Social Media Influencers' Data","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/02\/cyberselfie-mod.jpg","datePublished":"2018-02-07T14:13:43+00:00","dateModified":"2018-02-07T14:13:43+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541"},"description":"Upguard researcher announced the discovery of an unsecured AWS S3 cloud storage \u201cbucket\u201d from Octoly exposing 12,000 social media influencers' data.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/02\/cyberselfie-mod.jpg","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/02\/cyberselfie-mod.jpg","width":800,"height":400,"caption":"Will Facebook Force the Creation of a U.S. National Privacy Law?"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/amazon-web-services-bucket-leaks-12000-social-media-influencers-data\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"Amazon Web Services Bucket Leaks 12,000 Social Media Influencers&#8217; Data"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","description":"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541","name":"Ben Canner","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","caption":"Ben Canner"},"description":"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.","url":"https:\/\/solutionsreview.com\/identity-management\/author\/bcanner\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/2314"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/41"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=2314"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/2314\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media\/2315"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=2314"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=2314"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=2314"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}