December 30, 2015 By Larry Loeb 2 min read

Chris Vickery, the white-hat hacker who recently gained attention for exposing public-facing and hence easily accessible databases has now found something even worse: A database with the personal data of 191 million voters that is misconfigured to allow public access. What should the public know?

What Personal Data Is Exposed?

The political database contains over 300 gigabytes of information in total. The exposed personal data in the database includes full names, addresses, voter IDs, genders, phone numbers, dates of birth, political affiliation and voter history for millions of registered voters.

SecurityWeek reported that Vickery and others have searched the database for their own records to check the validity. They found the details stored in it were accurate.

Whose Database Is It?

But there is a larger problem here: Nobody will admit to actually owning the database. SecurityWeek noted that Vickery has been assisted by fellow researchers at DataBreaches.net as well as Steve Ragan of CSO Online in trying to identify the owner responsible for the database.

The researchers have contacted a congressman’s political action committee and several political data firms, including Political Data, L2 Political, Aristotle, NGP VAN and Catalist, to try to identify the owner. So far, the team isn’t any closer to an answer, and the database is still online.

Could NationBuilder Be the Culprit?

SecurityWeek reported that NationBuilder, a tool often used for political campaigns, is currently the main suspect. Ragan noted that NationBuilder had said the IP address hosting the database wasn’t one of its own, and it wasn’t an IP address for any of their hosted clients.

“While the database is not ours, it is possible that some of the information it contains may have come from data we make available for free to campaigns. From what we’ve seen, the voter information included is already publicly available from each state government, so no new or private information was released in this database,” NationBuilder founder and CEO Jim Gilliam said in a statement to SecurityWeek.

However, Ragan believes that based on the voter count and the format of the records, the database is from one of NationBuilder’s 2014 updates. It seems that the voterID field is a clear marker to the source — but there’s still no confirmation.

Until more information is discovered, registered voters should be wary of any suspicious communications received, especially if they’re political in nature.

More from

What makes a trailblazer? Inspired by John Mulaney’s Dreamforce roast

4 min read - When you bring a comedian to offer a keynote address, you need to expect the unexpected.But it is a good bet that no one in the crowd at Salesforce’s Dreamforce conference expected John Mulaney to tell a crowd of thousands of tech trailblazers that they were, in fact, not trailblazers at all.“The fact that there are 45,000 ‘trailblazers’ here couldn’t devalue the title anymore,” Mulaney told the audience.Maybe it was meant as nothing more than a punch line, but Mulaney’s…

What’s up India? PixPirate is back and spreading via WhatsApp

8 min read - Quick recapThis blog post is the continuation of a previous blog regarding PixPirate malware. If you haven’t read the initial post, please take a couple of minutes to get caught up before diving into this additional content. As a reminder, PixPirate malware consists of two components: a downloader application and a droppee application, and both are custom-made and operated by the same fraudster group. Although the traditional role of a downloader is to install the droppee on the victim device,…

83% of organizations reported insider attacks in 2024

4 min read - According to Cybersecurity Insiders' recent 2024 Insider Threat Report, 83% of organizations reported at least one insider attack in the last year. Even more surprising than this statistic is that organizations that experienced 11-20 insider attacks saw an increase of five times the amount of attacks they did in 2023 — moving from just 4% to 21% in the last 12 months.With insider threats on the rise, it’s critical for businesses to recognize the real dangers that originate from inside…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today