Skip to content
June 19, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Data Leak
  • AgentRun data leak reveals personal sensitive information of customers
  • Data Leak

AgentRun data leak reveals personal sensitive information of customers

Do Son May 28, 2018 2 minutes read
Add as a preferred
source on Google

The US software company AgentRun has accidentally exposed the thousands personal sensitive information of policyholders recently. The reason is actually that of an unencrypted Amazon S3 bucket.

AgentRun is a software company based in Chicago, Illinois, United States. Founded in 2012 by former independent insurance broker and software engineer Andrew Lech, AgentRun specializes in providing client management software for insurance brokers.

Insecure Amazon S3 buckets contain large amounts of cached data, involving sensitive personal information from thousands of different insurance company customers, including customers of large insurers like Cigna and SafeCo Insurance. The leaked information may include insurance policy documents. , health and medical information, and some financial data.

ZDNet pointed out that insecure buckets are not password protected and anyone can access them. Andrew Lech, the founder of the company, confirmed the data event via email and stated that the problem was in the process of upgrading applications and data transfer. When the data was transferred to this bucket, the permissions of the bucket appeared artificial. error.

Lech said that the entire data breach lasted only about an hour because they immediately shut down the server after receiving notifications about the exposure of the bucket. During this period, the data that can be accessed by the public mainly include insurance policy documents, scanned copies of various documents, and some medical record files.

The policy document contains detailed policyholder personal information such as name, email address, date of birth, and telephone number. In some cases, some documents also show income ranges, race and marital status, and even a blank bank check.

For scans, various documents, such as social security cards, medical cards, driver’s licenses, voter cards, and military documents, are involved; medical record files contain information that can determine the medical status of policyholders, including the individual’s prescription, dosage, and cost.

In addition to Cigna and SafeCo, incident-influenced insurance companies include TransAmerica, SafeCo Insurance, Manhattan Life, and Everest. Lech said that they will notify all affected client companies and policyholders and will also notify the relevant authorities.

Related coverage

  • Unsecured Database Linked to Navy Federal Credit Union Exposed Online
  • Facebook have been collecting call logs and SMS metadata for several years
  • Microsoft PlayReady DRM Certificates Leaked: SL3000 Pulled from GitHub, Amazon Suspends Pirate Accounts
  • Mozilla suspends ads on Facebook due to privacy issues
  • “Stylish” browser extension collect user information

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: AgentRun

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-55884
    ## Summary The Tilt HUD HTTP server exposes state-changing and sensitive-read endpoints...
  • CVE-2026-9142CVSS 9.1
    There is an insecure default credentials vulnerability in NI grpc-device when TLS...
  • CVE-2026-54051CVSS 9.9
    ## Summary The agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`),...
  • CVE-2026-48137CVSS 9.1
    There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband...
  • CVE-2026-50242CVSS 10.0
    In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass...
  • CVE-2026-56142CVSS 9.6
    In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation...
  • CVE-2026-56141CVSS 9.8
    In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover...
  • CVE-2026-54414CVSS 9.8
    FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload...
  • CVE-2026-7515CVSS 9.8
    The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion...
  • CVE-2026-8713CVSS 9.1
    The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.