GovPayNet, a private company that provides online payment services to more than 2,300 U.S. government agencies in 35 states, leaked approximately 14 million records containing customer receipt information dating back to 2012.
According to Brian Krebs, a security researcher, the company's website, GovPayNow.com, allowed anyone to access receipt data ranging from traffic citations to fines to bail payments.
This happened because after processing payments, GovPayNow.com issued a digital receipt - to confirm the payment - which it displayed on the website, with no security measures beyond a unique identifier added to the page URL for each receipt

Therefore, it is very easy for someone to gain access to the receipt data of every customer who has ever used the GovPayNet payment system by simply changing the digits in the receipt identifiers. So a malicious user can simply view the full names, physical addresses and phone numbers of the receipt owners as well as the last four digits of the credit card used in the transaction through the site.
After discovering the bug, the security researcher notified GovPayNet of the issue and received a response two days later confirming its resolution.
GovPayNet, for its part, stressed that no personal customer information has been stolen by a malicious user. Furthermore, it assured that the receipt system has been updated and allows access to receipts only to certified and authorized users.
