An unsecured database with 93.4M Mexican voter records found hosted on AWS, now taken offline
Personal info of 93.4 million Mexicans exposed on Amazon (UPDATED) — In today's installment of “Epic Infosecurity #FAIL,” more than 93.4 million Mexican citizens have had their voter …
Context & Ripple Effects
This is the third major voter-database exposure in under five months, and the second this month alone. It follows the 191M-record US voter database left open with no identifiable owner in December, and the 55M-record Philippine voter leak including fingerprints earlier in April — making Mexico's registry part of a fast-emerging pattern rather than an isolated incident.
The distinguishing detail here is the hosting: unlike a breached government server, these 93.4M records sat on AWS, which puts a commercial cloud provider at the center of a national voter-data failure and revives questions about who is accountable when a customer's misconfiguration exposes an entire electorate — a question AWS itself would face again years later when it declined to take down an exposed birth-certificate database.
First-order effects
- Personal details of 93.4 million registered Mexican voters were readable by anyone who found the database until its removal, giving whoever accessed it names, addresses, and voting history tied to identifiable citizens.
- The database operator — unnamed in the reporting — now faces the exposure that its entire national-scale dataset was publicly accessible, while AWS hosts the story's reputational fallout as the platform where it sat.
Second-order effects
- Every organization storing electoral rolls on public cloud infrastructure comes under renewed scrutiny, since three leaks in five months show the failure mode is misconfiguration by the data holder, not an attack on the registry itself.
- Cloud providers face mounting pressure over their role in customer-caused exposures — a tension that resurfaces in the later AWS case where neither Amazon nor the collecting firm took the exposed data down after being alerted.
Third-order effects
- If voter registries keep leaking through misconfigured cloud storage, accountability shifts toward contractual and regulatory mechanisms that make data holders — not just platforms — provably responsible for access controls, the core premise of designing accountability into systems from the start.
- Election authorities may conclude that voter rolls are too sensitive to delegate wholesale to contractors on commodity cloud hosting, pushing toward stricter custody requirements for civic data across jurisdictions.
The trend: Voter databases worldwide are migrating onto commercial cloud infrastructure faster than their custodians are securing it, turning routine misconfiguration into whole-electorate exposures.