A security lapse exposed sensitive personal data from users of the Duc App, a money-transfer service owned by Toronto-based Duales. An Amazon-hosted storage server was left publicly accessible without password protection or encryption, allowing access to documents including passports, driver’s licenses, and transaction records.
Security researcher Anurag Sen identified more than 360,000 files, some dating back to 2020. The company restricted access after being alerted but did not confirm whether the data was accessed. Canada’s privacy regulator is investigating. The incident highlights ongoing concerns about data protection as fintech platforms collect sensitive identity information.
Want to know more? Check out the source code on TechCrunch.com.










