• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 25, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Data Leak
  • Misconfigured NAS Server, Lots of Insurance Customers’ Sensitive Data was Leaked
  • Data Leak

Misconfigured NAS Server, Lots of Insurance Customers’ Sensitive Data was Leaked

Ddos February 20, 2018 4 minutes read
NAS Server

The loss of customer privacy reminds us of previous information breaches in the credit repair and marketing industry, and the UpGuard cyber risk team now wants to talk about MDJIA’s disclosure case. Is a Maryland state-owned private property insurance company that leaks thousands of customers’ information online due to misconfiguration of storage devices. The data exposure again warns us that highly sensitive personally identifiable information could leak to the web, in which case the data was leaked through the open ports of a networked device.

Exposure to the compromised data store is a backup of the JIA client files and statements, including customer names, addresses, phone numbers, birthdays, social security numbers, checks, bank accounts, and policy numbers. In addition to this important customer information, this leak exposes a series of internal access credentials that were originally used to manage and control the MDJIA association’s operations, including remote desktops, email, third-party usernames, and passwords.

Due to misconfiguration, enterprises are bound to invest enough resources to protect the data. The exposure of the external platform access credentials once again highlights the potential threat of third-party vendors and business partners sharing information.

On January 19, 2018, Chris Vickery, director of online risk research at UpGuard, noticed MDJIA because he discovered a networked storage (NAS) device belonging to the insurance association. The device is connected to the Internet through an open port that contains key and sensitive data related to the IT operations of the Association. The data is split into two parts – Backup (the environment with a large number of insurance clients and claimant data) and Share (including vouchers and more A folder of internal administrator data).

The BBackup and Share folders.

An in-depth understanding of the Association’s operations is based on the data exposed, which is part of Maryland and, like similar organizations in other states was formed through the federal FAIR (Fair Assurance Requirements) program.

What is FAIR’s property insurance policy? How do organizations like MDJIA meet their needs? The purpose of the FAIR policy is to protect the owner of the property with claims from policyholders, or those who live in areas prone to natural disasters. Many of these property owners are considered by the insurer to be unqualified applicants because they do not meet the requirements of a policy and are over-insured. Thus, the FAIR policy provides an acceptable basic category of insurance for those who are easily rejected by insurance companies. Although a statewide insurance association like MDJIA is not a public agency, the state government has covered the coverage of the FAIR’s Market Share Program, a private equity fund, and its revenue must be returned to the project. The association is voluntarily formed by insurers in all markets, all licensed and also involved in writing Maryland’s basic, homeowner and multi-risk property risk provisions.

In Maryland, this means that all state insurers in the state have to contribute to the JIA association, which in turn helps property owners who are vulnerable to denial. Unfortunately, after the exposure of a backup subfolder called Live, thousands of such vulnerable customers are also exposed from this unprotected storage device.

The interior of the “Live” subfolder.

BBackup contains a large number of files, all of which are customer-oriented JIA association IT operations documents, from the application for insurance to the claim for compensation. These data contain a large number of personal identification information. A 60GB folder called “appgen” contains a subfolder with more than 175,000 files saved from 2012 to the present. A similar sub-folder called “DU” contains 149,000 files, all of which are the applicant’s name, address, and phone number.

Property inspection reports and claims submissions, such as property damage reports, provide more customer details. However, the most troublesome is the social security number in the “appgen” folder, as well as the policy number information, as well as a check image showing the full bank card number.

The “Share” folder contains sensitive information about MDJIA’s IT assets. Internal password list, including passwords for JIA email addresses saved as plain text, and screenshots of TeamViewer remote desktop access credentials.

The exposure to MDJIA ISO ClaimSearch access credentials is even more devastating, a third-party insurance database provided by Verisk Analytics that contains millions of individual claims reports that industry experts refer to – in the unlikely event of a malicious visit, It is a tremendous treasure trove of identification information.

Source: upguard

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Nearly 45,000 records of US health care company, Blue Springs Family Care were leaked
  2. Hacker sells Telus source code, and staff info for $50,000
  3. Sensitive information about U.S. House members and staff are being sold
  4. Thousands of API Secrets Exposed on Postman – Are Your Credentials At Risk?
  5. $115 Million Payout: Oracle Ends User Data Privacy Battle
Tags: NAS Server

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-9478CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the...
  • CVE-2026-9477CVSS 9.8
    A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue...
  • CVE-2026-9476CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the...
  • CVE-2026-9475CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function...
  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
  • CVE-2026-9454CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects...
  • CVE-2026-9436CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity © All rights reserved.