{"id":1396,"date":"2020-02-25T12:58:11","date_gmt":"2020-02-25T08:58:11","guid":{"rendered":"https:\/\/www.techxmedia.com\/?p=1396"},"modified":"2025-04-18T02:26:47","modified_gmt":"2025-04-17T22:26:47","slug":"plastic-surgery-photos-exposed-online","status":"publish","type":"post","link":"https:\/\/techxmedia.com\/en\/plastic-surgery-photos-exposed-online\/","title":{"rendered":"Sensitive plastic surgery photos exposed online"},"content":{"rendered":"\n<p><strong>By \u201cAmer Owaida\u201d, Security\nWriter at ESET<\/strong><\/p>\n\n\n\n<p>Hundreds of thousands of records belonging to plastic surgery patients have been discovered sitting on an unprotected server and accessible for anyone to view. The data were stored on an Amazon Web Services (AWS) S3 bucket database belonging to NextMotion, a plastic surgery <a href=\"https:\/\/techxmedia.com\/tag\/technology\/\">technology<\/a> company that provides imaging solutions to clinics around the world.<\/p>\n\n\n\n<p>Researchers at&nbsp;<a href=\"https:\/\/www.vpnmentor.com\/blog\/report-nextmotion-leak\/\" target=\"_blank\" rel=\"noreferrer noopener\">vpnMentor<\/a>, who\nuncovered the leak, were able to access some 900,000 individual records. These\nranged from before-and-after images and videos of cosmetic procedures to\nmaterials of a highly sensitive nature, including graphic photos of the\npatients\u2019 private body parts. The origin of the records is not clear but it can\nbe assumed that the leak affected NextMotion clients.<\/p>\n\n\n\n<p>Besides patient facial and body photos,\nthe trove of information included invoices, outlines of proposed treatments,\nand video files including 360-degree face and body scans. The invoices detailed\nthe medical procedures, their costs, dates when they were performed, and\npersonal information that could help identify patients.<\/p>\n\n\n\n<p>All things considered; the data could\nallow hackers with malicious intent to create a comprehensive portrait of their\npotential victims. The patients could then easily become targets of&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2020\/01\/02\/simple-steps-protect-identity-theft\/\" target=\"_blank\" rel=\"noreferrer noopener\">identity theft<\/a>,&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2016\/09\/22\/5-simple-ways-can-protect-phishing-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing<\/a>,&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2016\/06\/02\/beware-online-fraudsters-jumping-back-recent-data-breaches\/\" target=\"_blank\" rel=\"noreferrer noopener\">financial fraud<\/a>&nbsp;or even&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2019\/03\/19\/i-didnt-see-what-you-did-redux\/\" target=\"_blank\" rel=\"noreferrer noopener\">sextortion<\/a>, where\ncriminals use intimate material to demand a ransom.<\/p>\n\n\n\n<p>NextMotion CEO Dr. Emmanuel Elard&nbsp;<a href=\"https:\/\/www.nextmotion.net\/data-security\" target=\"_blank\" rel=\"noreferrer noopener\">apologized<\/a>,\nadding that the issue has been addressed: \u201cAmazon Web Service warned us on the\n30th of January. After internal discussions with Amazon\u2019s support, we\nimmediately took corrective steps on the 4th February. The cybersecurity\ncompany formally guaranteed that the security flaw had completely disappeared.\u201d<\/p>\n\n\n\n<p>As NextMotion is headquartered in France\nand offers services in the European Union (EU), it is subject to the EU\u2019s&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/category\/gdpr\/\" target=\"_blank\" rel=\"noreferrer noopener\">General Data Protection Regulation<\/a>&nbsp;(GDPR). Although the company\u2019s website states that its technology is\nGDPR certified, the failure to secure patients\u2019 sensitive data may carry stiff\npenalties and legal actions.<\/p>\n\n\n\n<p>Misconfigured and&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2016\/06\/10\/drip-flood-impact-data-leak\/\" target=\"_blank\" rel=\"noreferrer noopener\">unsecured public-facing data repositories<\/a>&nbsp;have become a common occurrence. In one recent case,&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2019\/12\/10\/data-leak-exposes-750000-birth-certificate-applications\/\" target=\"_blank\" rel=\"noreferrer noopener\">thousands of birth certificate applications<\/a>&nbsp;were stored unprotected on an AWS cloud platform, while another&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2019\/09\/17\/ecuador-citizens-data-leak\/\">data leak\naffected almost all of Ecuador\u2019s citizens<\/a>. These leaks were unintentional, but there have been cases where\ncosmetic surgery clinics, such as a&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2017\/10\/24\/plastic-surgery-hacking-dark-overlord\/\" target=\"_blank\" rel=\"noreferrer noopener\">well-known clinic in London<\/a>, were\ntargeted by cybercriminals.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers at vpnMentor, who uncovered the leak, were able to access some 900,000 individual records. These ranged from before-and-after images and videos of cosmetic procedures to materials of a highly sensitive nature, including graphic photos of the patients\u2019 private body parts. The origin of the records is not clear but it can be assumed that the leak affected NextMotion clients.<\/p>\n","protected":false},"author":8,"featured_media":1398,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[54,9624],"tags":[540,518,539,538],"contributor":[],"class_list":["post-1396","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-health-tech","category-smart-sectors","tag-amazon_web_services","tag-cyber_security","tag-medical_technology","tag-plastic_surgery"],"featured_image_src":"https:\/\/techxmedia.com\/en\/wp-content\/uploads\/2020\/02\/Amer-Owaida-Security-Writer-at-ESET-e1582620897336.jpg","author_info":{"display_name":"Rabab","author_link":"https:\/\/techxmedia.com\/en\/author\/rabab\/"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/1396","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/comments?post=1396"}],"version-history":[{"count":0,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/1396\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media\/1398"}],"wp:attachment":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media?parent=1396"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/categories?post=1396"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/tags?post=1396"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/contributor?post=1396"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}