May 16, 2026
ManyPress
Technology

A hotel check-in system left a million passports and driver’s licenses open for anyone to see

A hotel check-in system left more than 1 million customer passports, driver’s licenses, and selfie verification photos to the open web after a security lapse. The data is now offline after TechCrunch

NF

ManyPress Editorial Team

ManyPress Editorial

May 15, 2026 · 6:51 PM3 min readSource: TechCrunch
A hotel check-in system left a million passports and driver’s licenses open for anyone to see

A hotel check-in system left more than 1 million customer passports, driver’s licenses, and selfie verification photos to the open web after a security lapse. The data is now offline after TechCrunch alerted the company responsible. The hotel check-in system, called Tabiq , is maintained by the Japan-based tech startup Reqrea .

According to its website, Tabiq is used in several hotels across Japan and relies on facial recognition and document scanning to check guests in. Independent security researcher Anurag Sen contacted TechCrunch earlier this week after discovering that the system was leaking the sensitive documents of hotel guests from around the world. Sen said this was because the startup set one of its Amazon cloud-hosted storage buckets, which the check-in system uses to store customer data, to be publicly accessible. The data inside could be viewed by anyone using a web browser, without needing a password, by knowing only the bucket name: “tabiq.” Sen alerted TechCrunch in an effort to help notify the company. Reqrea locked down the storage bucket after TechCrunch reached out to both the company and Japan’s cybersecurity coordination team, JPCERT . This latest lapse underscores a recurring problem of companies exposing or spilling their customers’ personal information and sensitive documents — not through sophisticated attacks, but by failing to follow basic cybersecurity practices. Aside from a recent buzz of AI-discovered vulnerabilities and new cybersecurity capabilities , oftentimes sizable security incidents stem from human error, misconfigurations, or failing to adhere to cybersecurity best practices. In an email acknowledging the exposure, Reqrea director Masataka Hashimoto told TechCrunch: “We are conducting a thorough review with the support of external legal counsel and other advisors to determine the full scope of exposure.” Reqrea said it does not know how the storage bucket became public. By default, Amazon’s cloud storage buckets are private. After a spate of exposed customer storage buckets a few years ago, Amazon added several warning prompts to customers before data can be made public, making this kind of lapse increasingly hard to do accidentally. Hashimoto told TechCrunch that the company plans to notify affected individuals once it has completed its investigation. It remains unclear whether anyone other than Sen accessed the exposed data before it was secured.

Key points

  • According to its website, Tabiq is used in several hotels across Japan and relies on facial recognition and document scanning to check guests in.
  • Independent security researcher Anurag Sen contacted TechCrunch earlier this week after discovering that the system was leaking the sensitive documents of hotel guests from around the world.
  • Sen said this was because the startup set one of its Amazon cloud-hosted storage buckets, which the check-in system uses to store customer data, to be publicly accessible.
  • The data inside could be viewed by anyone using a web browser, without needing a password, by knowing only the bucket name: “tabiq.” Sen alerted TechCrunch in an effort to help notify the company.
  • Reqrea locked down the storage bucket after TechCrunch reached out to both the company and Japan’s cybersecurity coordination team, JPCERT .

AdvertisementAd Placeholder — Configure AdSense in .env.localNEXT_PUBLIC_ADSENSE_CLIENT=ca-pub-XXXXXXXX

This article was independently rewritten by ManyPress editorial AI from reporting originally published by TechCrunch.

Technology