Security firm vpnMentor has discovered that more than a million fingerprints and sensitive personal data are exposed online.
The company's researchers said that early last month, they discovered such data being stolen through the BioStar 2 security tool and stated that this breach has been stopped. Moreover, the data that was leaked was personal information of employees of various companies, unencrypted usernames and passwords , etc. The hackers used the data they extracted to gain access to services and facilities, in order to transform security protocols in order to commit criminal acts. In essence, these are attacks that harm not only the employees they target, but also the company itself.

Suprema , etc. In order for someone to enter facilities using BioStar 2, their fingerprints and facial recognition are required.
Two security researchers, Noam Rotem and Ryan Locar, from Israel working with vpnMentor, are looking to find holes in companies' systems that could potentially lead to data breaches. They discovered that the BioStar 2 database was not encrypted and thus remained unprotected.

They also discovered that they had access to more than 27.8 million files and 23 gigabytes of data, including fingerprints, facial recognition, user, unencrypted usernames and passwords, and personal information of staff.
The sheer scale of the breach is alarming because the service is located in various locations around the world and because, unlike leaked passwords, when fingerprints are leaked, they cannot simply be changed.
According to security researchers, of course, the phenomenon is very common, since they come into contact with companies facing the same problem very often. As they stated, three or four times a week.
