ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

LPM Property Management exposes over 31,000 sensitive documents in Amazon S3 bucket breach

A significant data security breach involving New Zealand-based LPM Property Management has exposed over 31,000 sensitive documents through a misconfigured Amazon S3 bucket. The leaked data includes passports, driver’s licenses, and ID verification photos belonging to tenants, landlords, and maintenance personnel, potentially placing thousands at risk of identity theft and fraud.


The breach was discovered by Jake Dixon, a security researcher at Vadix Solutions, who identified the publicly accessible Amazon Simple Storage Service (S3) bucket and alerted both LPM and CyberNews. Despite multiple attempts to reach LPM Property Management starting in May, neither Dixon nor CyberNews received a response. It was only after Amazon Web Services (AWS) was contacted directly that the exposed data was finally secured on July 6—nearly two months after the initial discovery.


The unsecured database contained a total of 31,610 files, of which only 15 were not images. The majority of the content included highly sensitive personal identifiable information such as New Zealand and foreign passports (both active and expired), driver’s licenses with ID numbers, birth dates, addresses, and photos of individuals applying for or involved in property management services. Additional files labeled as “maintenance requests” contained images of property damage, further linking individuals to specific rental units.


According to CyberNews, the leaked data could be valued between $442,000 and $632,000 on the dark web, based on typical prices for stolen passport and license scans. Such a cache of documents could be exploited for identity theft, loan fraud, and targeted phishing campaigns.


The exact duration for which the data was exposed and whether it was accessed by malicious actors remains unclear. Due to the ease of accessing the files using a simple URL, experts believe the information could have already been compromised. Security specialists are advising affected individuals to monitor for signs of fraud and phishing attempts and to consider enrolling in identity theft protection services.


Declan Ingram, Deputy Director of New Zealand’s Computer Emergency Response Team (CERT NZ), emphasized the severity of such security oversights and urged businesses to adopt stronger protective measures. “An unsecured database can be a huge risk to customers’ privacy and security,” Ingram said. He recommended organizations implement long passwords, two-factor authentication, and network segmentation, especially for systems storing sensitive data. “By ensuring that all networks are segmented to control who can access them, businesses reduce the likelihood of unauthorized access to the data in those systems,” he added.


Despite repeated outreach, LPM Property Management has not issued a statement regarding the breach and continues to remain silent on the matter. AWS confirmed it took action to secure the data after the vendor failed to respond to initial warnings.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543