
A significant data exposure incident has come to light, involving a dataset containing 820,750 records amounting to 122GB of information. Security researcher Jeremiah Fowler discovered the unprotected database, which is believed to belong to Lost & Found, a German tracking software firm primarily serving the aviation industry.
The exposed dataset consisted of 14 databases, 10 of which were publicly accessible while four remained restricted. Among the data discovered were shipping labels, lost item reports, and screenshots detailing personal belongings such as electronic devices, wallets, bags, medical instruments, and other effects commonly transported by air travelers. Additionally, the dataset included personally identifiable documents such as passport scans, driver’s licenses, and employment records. These documents may have been either misplaced and uploaded by airport staff or used to file claims and verify ownership of lost property.
Upon notification of the exposure, access to the databases was restricted within hours. However, it remains uncertain whether Lost & Found directly managed the databases or if a third-party contractor was responsible for their oversight. Additionally, the duration of the exposure and whether malicious actors accessed the information before its restriction remain unknown.
Given the nature of the compromised data, those affected face a heightened risk of identity theft. Criminals could potentially exploit passport and ID scans to fraudulently obtain loans, open bank accounts, or conduct other forms of financial fraud. As a precaution, individuals concerned about potential exposure are advised to monitor their financial accounts, scrutinize transactions, and report any suspicious activity to their banks immediately.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543