Substrate
technology

Over One Million Hotel Guest ID Photos Left Publicly Accessible in Cloud Storage

A Japan-based startup's misconfigured Amazon cloud storage bucket left sensitive guest identity documents from hotels using its Tabiq system publicly accessible for years. Independent researcher Anurag Sen discovered the exposure and alerted TechCrunch, prompting the company to secure the data.

TechCrunch
1 source·May 15, 6:51 PM(13 days ago)·2m read
|
Over One Million Hotel Guest ID Photos Left Publicly Accessible in Cloud Storageonemileatatime.com
Audio version
Tap play to generate a narrated version.
Developing·Limited corroboration so far. This page will refresh as more sources emerge.

More than one million customer passports, driver’s licenses, and selfie verification photos from a hotel check-in system called Tabiq were left publicly accessible on the open web. The Japan-based tech startup Reqrea, which maintains Tabiq, had set one of its Amazon cloud-hosted storage buckets to be publicly accessible.

The exposure occurred because the bucket named “tabiq” allowed anyone using a web browser to view the data without needing a password by knowing only the bucket name.

Independent security researcher Anurag Sen discovered that the Tabiq system was leaking sensitive documents of hotel guests from around the world. Sen contacted TechCrunch earlier this week. TechCrunch alerted the company responsible for the exposure and also reached out to Japan’s cybersecurity coordination team, JPCERT.

Reqrea locked down the storage bucket after those notifications. The data exposure has been taken offline. Details of the exposed bucket were captured by GrayHatWarfare, a searchable database that indexes publicly visible cloud storage.

The bucket listing contains files dating back to early 2020 up to as recently as May 2026. Tabiq is used in several hotels across Japan. According to its website, the system relies on facial recognition and document scanning to check guests in.

Reqrea said it does not know how the storage bucket became public. Amazon’s cloud storage buckets are private by default. Hashimoto told TechCrunch that the company plans to notify affected individuals once it has completed its investigation.

Hashimoto said the company is reviewing its logs to determine if there had been any unauthorized access prior to securing the bucket. It remains unclear whether anyone other than Sen accessed the exposed data before it was secured. TechCrunch reported that this latest lapse follows other incidents involving sensitive government-issued documents.

Earlier this year, TechCrunch reported on the exposure of driver’s licenses, passports, and other identity documents uploaded by customers of money transfer service Duc App. A data breach at car rental service Hertz last year saw hackers make off with driver’s license information belonging to at least 100,000 customers.

These incidents come at a time when governments are increasingly rolling out age verification laws and private businesses are using “know your customer” checks to verify a person’s identity.

Both rely on adults uploading sensitive documents, often to a third-party company, for verification. Data lapses can put people whose information was taken at greater risk of identity fraud or having their likeness misused as age verification requirements take hold around the world.

Key Facts

Over one million identity documents exposed via Tabiq system
More than one million customer passports, driver’s licenses, and selfie verification photos from Tabiq, used in several hotels across Japan, were publicly acces
Researcher Anurag Sen discovered and reported the exposure
Independent security researcher Anurag Sen found the publicly accessible bucket, contacted TechCrunch earlier this week, and explained that knowing only the buc
Reqrea director Masataka Hashimoto acknowledged the lapse
Hashimoto stated the company is conducting a thorough review with external legal counsel, does not know how the bucket became public, is reviewing logs for unau
Bucket contained files spanning more than six years
The GrayHatWarfare database captured the exposed bucket listing files dating back to early 2020 up to as recently as May 2026, including identity documents from

Story Timeline

4 events
  1. 2026-05

    Files in the exposed Tabiq storage bucket dated as recently as May 2026

    1 sourceTechCrunch
  2. 2026-05 (earlier this week)

    Anurag Sen discovered the leak and contacted TechCrunch

    2 sourcesAnurag Sen · TechCrunch
  3. 2026-05 (after contact)

    TechCrunch alerted Reqrea and JPCERT; company locked down the bucket

    1 sourceTechCrunch
  4. 2020-2026

    Exposed files dated from early 2020 through May 2026

    1 sourceGrayHatWarfare via TechCrunch

Potential Impact

  1. 01

    Reqrea must notify potentially over one million individuals after completing its internal review

  2. 02

    Further damage to trust in third-party KYC and identity verification providers

  3. 03

    Increased regulatory and public scrutiny of facial recognition and document scanning systems used for hotel check-ins and age verification

  4. 04

    Affected hotel guests face elevated risk of identity fraud and misuse of facial verification photos

Transparency Panel

Sources cross-referenced1
Confidence score75%
Synthesized bySubstrate AI
Word count406 words
PublishedMay 15, 2026, 6:51 PM
Bias signals removed3 across 2 outlets
Signal Breakdown
Loaded 2Speculative 1

Related Stories

World Urban Forum 2026 Draws 57,000 Participants from 176 CountriesEuronews
technology4 hrs agoDeveloping

World Urban Forum 2026 Draws 57,000 Participants from 176 Countries

The 13th World Urban Forum concluded with discussions on housing, climate resilience and urban governance. Organisers reported that the sessions informed future strategic priorities.

Euronews
1 source
Trump Mobile website still lists T1 phone as American-madetheverge.com
technology4 hrs agoDeveloping

Trump Mobile website still lists T1 phone as American-made

The product page for the T1 phone continues to describe the device as American-made. The Verge reported that the site may conflict with FTC advertising rules. The phone was announced in June 2025.

The Verge
1 source
EU Discusses Readiness for Artificial Intelligence ChangesFrance 24
ai4 hrs agoDeveloping

EU Discusses Readiness for Artificial Intelligence Changes

A France 24 program examined whether European Union policies can address the effects of artificial intelligence. The discussion covered potential impacts across daily life and economic sectors.

France 24
1 source