Tabiq, a hotel check-in system operated by Japanese startup Reqrea, left more than 1 million customer passports, driver's licenses, and selfie verification photos exposed on the open web after a security lapse. Independent security researcher Anurag Sen discovered the exposure and alerted the company.
Tabiq is used in several hotels across Japan and relies on facial recognition and document scanning to check guests in. The leaked files included identity documents of visitors from countries around the world.
Sen said the leak was caused by the startup setting one of its Amazon cloud-hosted storage buckets to be publicly accessible. The bucket could be viewed by anyone using a web browser without needing a password by knowing only its bucket name, "tabiq." By default, Amazon's cloud storage buckets are private, and after previous incidents of exposed customer storage buckets, the company added several warning prompts to customers before data can be made public.
The bucket listing contained files dating back to early 2020 up to May 2026. Its details were captured by GrayHatWarfare, a searchable database that indexes publicly visible cloud storage.
Reqrea does not know how the storage bucket became public. "We are conducting a thorough review with the support of external legal counsel and other advisors to determine the full scope of exposure." Reqrea director Masataka Hashimoto said the company plans to notify affected individuals once it has completed its investigation, and is reviewing its logs to determine if there had been any authorized access prior to securing the bucket.
It remains unclear whether anyone other than Sen accessed the exposed data before it was secured. Hashimoto said the company is reviewing its logs to determine if there had been any unauthorized access prior to the bucket being secured.
The incident follows other exposures of identity documents held by private companies. Customers of money transfer service Duc App had their driver's licenses, passports, and other identity documents exposed earlier in 2026. A data breach at car rental service Hertz in 2025 saw hackers steal driver's license information belonging to at least 100,000 customers.
Governments are increasingly rolling out age-verification laws, and private businesses are using know your customer checks to verify a person's identity. The Tabiq exposure, which included files dating back to early 2020, illustrates the range of identity data that companies now collect and store on behalf of customers.
forum Comments (0)
No comments yet. Be the first to comment.