Plastic surgery is ???? ???more mainstream than it's ever been, but that doesn't mean patients are dying to have their cosmetic laundry aired in public.
Security researchers at vpnMentor discovered that about 900,000 images and invoices from cosmetic surgery imaging company NextMotion were sitting on an unsecured database in cloud storage. The exposed files included detailed invoices of procedures, as well as explicit images and 360-degree videos of patients' faces and bodies, including breasts and genitalia.
The report (via CNET) found that the breach could affect thousands of patients whose doctors use technology and software provided by NextMotion at 170 clinics around the world. The researchers discovered the vulnerable database during their "web mapping" project, which scans the internet and cloud for weaknesses.
"Our team was able to access this database because it was completely unsecured and unencrypted," the report reads.
That's contrary to NextMotion's claims on its website that "all your data is 100% secure." The culprit of the breach was a NextMotion Amazon Web Services (AWS) S3 bucket, a kind of digital cloud storage technology akin to a file folder. S3 buckets have been linked again and again to exposed databases of customer information when companies fail to secure them properly.
The researchers contacted NextMotion when they discovered the vulnerability and it has since been secured.
"We immediately took corrective steps and this same company formally guaranteed that the security flaw had completely disappeared," NextMotion writes on its website.
Cases of bungled cloud storage seem a dime a dozen these days, but the common scenario — of a company not taking the appropriate steps to obscure and secure its online databases — takes on a new and disturbing urgency when the content contains medical records and, frankly, nude photos. The images contained identifying information of patients, as well as before-and-after photos of procedures.
Even if everyone from Bella Hadid to your coworker Jill in marketing is getting a Botox brow lift, they don't necessarily want the world to know.
Topics Cybersecurity
Ecovacs Deebot X9 Pro Omni: $300 off at AmazonStunning Webb telescope photo shows an unbelievable number of galaxiesNYT Strands hints, answers for June 9Perseid meteor shower 2023: How to see themNASA finds a harsh world possibly packed with volcanoesWWDC 2025 rumor: MacOS Tahoe might run on fewer Macs than expectedNASA's new special Webb image shows chaos and creationChina’s NIO reportedly aims to make profit in Q4 · TechNodeTikTok star Khaby Lame was detained by ICE. Here's what happened.Mars spacecraft looks back and snaps poignant view of Earth Amazon Prime Video ads to double, report says Amber Tamblyn confronts male ‘redemption’ after sexual misconduct in ‘NYT’ op Of course Chrissy Teigen celebrated her birthday Pan Prince Harry's response when asked about fiancée Meghan Markle is as perfect as the ring NYT Strands hints, answers for June 12 Reddit updates homepage for net neutrality support ahead of FCC ruling Tiffany Haddish had the distinct honor of teaching Barbra Streisand all about Cardi B No one could make sense of the optical illusion dog. Can you? Trump's 'Time' tweet got better with every internet spoof Trump praises Native Americans and uses racial slur in the same sentence
0.1636s , 9825.6640625 kb
Copyright © 2025 Powered by 【???? ???】Plastic surgery photos and records exposed in unsecured database,Feature Flash