Drooid Logo
Back to story perspectives

Full Breakdown

Massive Data Exposure via Tabiq Hotel Check-In System Highlights Cloud Misconfiguration Risks

5/16/2026, 10:39:17 PM

Unsecured Cloud Bucket Exposes Over One Million Guest Documents

The Japanese-based startup Reqrea’s Tabiq check-in platform stored passports, driver’s licences and selfie verification photos in an Amazon Web Services S3 bucket named “tabiq”. The bucket was publicly accessible, allowing anyone with a web browser to view the files without authentication. The leak comprised more than one million identity records collected from early 2020 through May 2026.

Misconfiguration of an AWS S3 Bucket Triggers the Leak

AWS S3 buckets default to private and issue multiple warnings before being made public. In this case the bucket was deliberately set to “public” despite those safeguards, a basic configuration error rather than a sophisticated cyber-attack. The exposure persisted until a researcher identified it.

Key Actors and Timeline

  • Anurag Sen – independent security researcher who discovered the open bucket.
  • Masataka Hashimoto – director of Reqrea, who announced the company’s review.
  • TechCrunch – media outlet that received Sen’s report and alerted Reqrea and Japan’s cybersecurity coordination team JPCERT.
  • GrayHatWarfare – searchable database that indexed the publicly visible bucket.

Timeline: early 2020 – first guest data uploaded; May 2026 – newest files in the bucket; early May 2026 – Sen reports the public bucket; 15 May 2026 – TechCrunch publishes the story; Reqrea locks the bucket and begins a forensic review.

Data & Statistics

Over one million passports, driver’s licences and selfie photos were exposed, containing names, dates of birth, passport numbers, licence numbers, home addresses and facial images. Guests span many nationalities; Indian travelers form a sizable share because of high Japan-India tourism volumes.

Why It Matters for Travelers, Especially Indian Citizens

Exposed documents can enable bank-account fraud, counterfeit identity creation, social-engineering scams and dark-web sales. For Indian nationals, the breach may violate the Digital Personal Data Protection (DPDP) Act, which obliges data fiduciaries to implement “reasonable security” safeguards for personal data.

Official Statements & Responses

Reqrea director Masataka Hashimoto told TechCrunch that the company is conducting a thorough review with external legal counsel to determine the full scope of exposure. The firm locked the bucket, began log analysis and pledged to notify affected individuals once the investigation concludes.

Criticism & Opposition

Cybersecurity experts note that open-bucket incidents recur when companies fail to apply even the most elementary security settings. The hospitality sector’s growing reliance on facial-recognition kiosks adds risk when raw identity images are stored without encryption or strict access controls.

Conflicting Reports & Gaps

Reqrea has not disclosed how long the bucket remained public nor confirmed whether any third parties downloaded the data. Although GrayHatWarfare indexed the bucket, the extent of any secondary distribution remains unknown.

Verbatim Quotes

  • “We are conducting a thorough review with the support of external legal counsel and other advisors to determine the full scope of exposure.” — Masataka Hashimoto, Director, Reqrea
  • “TechCrunch also noted that the bucket was indexed by GrayHatWarfare, a searchable database that tracks publicly visible cloud storage.” — TechCrunch report
  • “The bucket listing contains files dating back to early 2020 up to as recently as this month, and included identity documents of visitors from countries around the world.” — TechCrunch article
  • “The DPDP Act requires companies collecting personal data of Indian citizens to implement reasonable security safeguards.” — CareerTechInsight analysis

What’s Next

Reqrea will issue breach notifications, complete a forensic audit and revise its data-retention policies. Indian regulators are expected to examine compliance with the DPDP Act, while industry groups call for mandatory security audits of all cloud-based identity-verification services.