Observed Signal · May 15, 2026 · Data Exposure · Source: techcrunch · Impact: 3/5 · Sentiment: Negative

Hotel check-in system exposed over one million IDs

Executive Signal Summary

A Japan-based hotel check-in system called Tabiq, maintained by startup Reqrea, left more than one million passports, driver’s licenses and selfie verification photos publicly accessible after a cloud storage misconfiguration. Independent researcher Anurag Sen discovered the exposed files in an Amazon-hosted storage bucket named "tabiq" and alerted TechCrunch; Reqrea secured the bucket after being notified and engaged external counsel while JPCERT was also contacted. The bucket contained records dating from early 2020 through May 2026 and was indexed by GrayHatWarfare. Reqrea says it is investigating the scope of the exposure and plans to notify affected individuals. The incident highlights recurring risks from cloud misconfigurations in identity-verification and KYC workflows.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Large-scale exposure of identity documents underscores operational security risks in cloud-hosted identity-verification services and raises regulatory, fraud and privacy concerns for KYC/age-verification workflows.

SIGNAL RADAR

Track Amazon Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Reqrea’s hotel check-in system Tabiq exposed more than one million passports, driver’s licenses and selfie verification photos on the public web.
  • Anurag Sen, an independent security researcher, discovered the exposure and alerted TechCrunch.
  • The data was accessible via an Amazon cloud storage bucket named "tabiq" that had been set to public; Reqrea locked the bucket after being notified.
  • GrayHatWarfare indexed the bucket listing, which contained files dating from early 2020 through May 2026.
  • Reqrea director Masataka Hashimoto said the company is conducting a review with external legal counsel and plans to notify affected individuals after investigation.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: May 15, 2026
Original Coverage Title: “A hotel check-in system left a million passports and driver’s licenses open for anyone to see”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

PrivacySep 10, 2026

IDScan confirms data breach of 150 million driver's licenses

Identity verification service IDScan has confirmed a data breach involving the theft of over 150 million driver's license records from its cloud systems. The stolen data includes full names, driver's license numbers, and other government ID numbers such as passports. The breach, which occurred over a year-long hack, was first reported by cybersecurity journalist Brian Krebs. IDScan, based in Louisiana, serves corporate clients including entertainment venues and cannabis dispensaries. The company acknowledged the incident on September 1 after receiving information about a claim of a hack, and its investigation is ongoing. The FBI and Pentagon are reportedly investigating. The stolen database is accessible on the dark web, with searchable records including photos.

Read assessment
IdentityApr 2, 2026

Duc App Exposed Hundreds of Thousands of ID Documents

A publicly accessible Amazon-hosted storage server containing unencrypted identity documents and personal data collected by the Duc App (owned by Toronto-based Duales) was exposed to the open web. Security researcher Anurag Sen of CyPeace discovered the misconfigured storage server listing over 360,000 files that included driver’s licenses, passports, selfies, and spreadsheets with names, addresses and transaction details. TechCrunch alerted Duales’ CEO Henry Martinez González, after which the files were made inaccessible; a listing of the server contents remained visible. The company said the data was on a "staging site." Canada’s privacy regulator has reached out to Duales for more information. The exposure dated back to September 2020 and the Duc Android app shows over 100,000 downloads on Google Play.

Read assessment
Privacy / Data BreachMay 27, 2026

UK Visa Portal Exposed Thousands' Passports and Selfies

A third-party site called UK Visa Portal publicly exposed thousands of passport images, selfies and location data uploaded by customers seeking U.K. immigration visas. An anonymous tipster told TechCrunch the site exposed at least 100,000 documents; TechCrunch verified the leak and contacted affected individuals. The exposure was caused by files hosted on an Amazon storage bucket that were accessible via direct file URLs, and many images contained precise location (EXIF) data. TechCrunch says the bucket was secured hours after publication. UK Visa Portal did not provide direct management contacts and referred TechCrunch to attorneys and a PR firm; the company is allegedly run by Active Leadgen LLC based in the UAE. It is not affiliated with the U.K. government.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.