Tech

Reqrea’s Tabiq system exposes one million passports and driver’s licenses in cloud misconfiguration

Over 1 million records, including selfie verification photos and identity documents from 2020 to May 2026, were left open on the open web before being secured following alerts from TechCrunch and JPCERT.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: TechCrunch · original
A hotel check-in system left a million passports and driver’s licenses open for anyone to see
Japan-based startup admits to security lapse after independent researcher discovers publicly accessible Amazon storage bucket

A security misconfiguration in the Tabiq hotel check-in system has left more than one million customer passports, driver’s licenses, and selfie verification photos publicly accessible on the open web. The data, maintained by Japan-based tech startup Reqrea, was exposed due to an Amazon cloud storage bucket being set to public, allowing unrestricted access without a password.

Independent security researcher Anurag Sen identified the vulnerability after discovering that the storage bucket, named “tabiq,” could be viewed by anyone using a web browser. The exposed files span from early 2020 to May 2026, containing identity documents from visitors to hotels across Japan and other countries. Details of the exposed bucket were also indexed by GrayHatWarfare, a searchable database of publicly visible cloud storage.

The data was secured after TechCrunch alerted both Reqrea and Japan’s cybersecurity coordination team, JPCERT. Reqrea director Masataka Hashimoto acknowledged the exposure in an email, stating the company is conducting a thorough review with external legal counsel and other advisors to determine the full scope of the incident.

Hashimoto noted that Reqrea does not know how the storage bucket became public. By default, Amazon cloud storage buckets are private, and the company added warning prompts to prevent accidental public access following previous incidents. Reqrea is currently reviewing logs to determine if any unauthorised access occurred prior to securing the bucket.

The company plans to notify affected individuals once the investigation is complete. This incident follows other recent exposures of sensitive documents, including data from money transfer service Duc App and car rental service Hertz, highlighting the risks associated with third-party identity verification services.

Continue reading

More from Tech

Read next: Apple to roll out manual EQ controls for AirPods in iOS 27 update
Read next: Apple rolls out visionOS 27, integrating AI-driven Siri into Vision Pro headset
Read next: Apple Overhauls Siri with Google Gemini Partnership and Standalone App at WWDC 2026