198 million American voter records found unprotected on the internet

You’d think if someone had amassed personal information on nearly every registered US voter, and stored that information on an Amazon S3 storage bucket, that it would at least be protected with a password. But thanks to a misconfigured server, personal data of 198 million Americans voters could be downloaded by anyone who happened across it. It is believed to be the largest leak of voter records to have ever occurred anywhere in the world.

That giant oops caused by Deep Root Analytics, a data analytics firm contracted to compile the information for the Republican National Committee, contained names, birthdates, home and mailing addresses, phone numbers, party affiliations, suspected ethnicities and religions, as well as analytics on who people would likely vote for and their stance on hot-button issues such as gun control and abortion.

The exposed and unsecured server was discovered by Chris Vickery, a cyber risk analyst for UpGuard. While scanning the web for publicly accessible servers, he discovered the data on the Deep Root Analytics Amazon subdomain “dra-dw” which stands for Deep Root Analytics Data Warehouse.

It contained personal information on almost every American voter – 198 million of America’s 200 million voters. The exposed server even contained bizarre bits of data. One of Deep Root’s folders is all about Reddit, containing 170 GBs of data scraped from subreddits. Although the server belonged to Deep Root, it also contained data compiled by other data analytic firms on behalf of the Republican Party: Target Point Consulting, Inc. and Data Trust.