Security researchers have discovered 49,000 exposed and poorly configured Access Management Systems (AMS), which could compromise the privacy and physical safety of people working in critical sectors, in multiple countries.

Access management systems are security systems that control employee access to buildings, facilities and restricted areas. Control is usually done through biometrics, ID cards or license plates.
Security researchers at Modat conducted a survey in early 2025 and discovered tens of thousands of AMS systems that were exposed to the Internet and were not properly configured for secure authentication. As a result, anyone could have access to them.
See also: Hackers can gain access to buildings – How is it done?
The systems contained sensitive unencrypted employee data:
- Personal identification information (names, email addresses, phone numbers)
- Biometric data such as fingerprints and facial recognition
- Photos
- Working hours
- Access to logs indicating who logged in/out and when
In some cases, Modat could edit employee records, add fake employees, change access credentials , or manipulate building entry systems. Doing so could prevent legitimate employees from accessing the buildings or allow third parties to enter.
This means that in addition to unauthorized access to employee data, there is also a significant risk to the physical safety of people in government buildings and critical infrastructure.
Of the total 49,000 exposed access management systems, the most (16,678) are located in Italy , followed by Mexico (5,940) and Vietnam (5,035). In the US, Modat found 1,966 exposed AMS systems.
The researchers contacted all system owners to inform them of the risk, but have not received a response. System vendors have also been notified, with some saying they are working with customers to fix the problem.
See also: OpenAI blocked ChatGPT accounts of North Korean hackers

Modat provided several security recommendations for users of access management systems.
- He suggested taking systems offline to prevent unauthorized remote access and using firewalls and VPNs to limit access to authorized personnel only.
- It is also recommended to change the default administrator credentials, and enable multi-factor authentication (MFA).
- As with all other digital systems, AMSs should have the latest software and firmware to correct potential security issues.
- Biometric data and personal information of employees should always be stored in encrypted form and data of former employees should be deleted.
- Monitoring and recording access activities in real time can help to immediately identify and respond to suspicious activities. Intrusion Detection Systems (IDS) can enhance this effort.
- Implementing regular security audits and penetration testing can help identify and fix vulnerabilities before they are exploited by malicious actors. These tests simulate attacks and assess the resilience of systems.
- Finally, system administrators must be trained in security best practices and constantly updated on new threats. Hackers are always finding new ways to penetrate systems, so we must always be vigilant.
See also: Hackers target organizations with NailaoLocker ransomware
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
