/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Fingerprints of 1M+ people and biometric info from a system used by banks, London police, and defense contractors, discovered on a publicly accessible database

Fingerprints, facial recognition and other personal information from Biostar 2 discovered on publicly accessible database

The Guardian Josh Taylor

Context & Ripple Effects

Biostar 2 is not a consumer app — it is the access-control layer that banks, the London Metropolitan Police, and defense contractors use to gate physical entry, which is what makes a publicly readable copy of its data so damaging. The find also fits a pattern in the related coverage: an unprotected Beijing surveillance database matching faces to police records surfaced months earlier, and researchers keep finding that the most sensitive identity stores are the ones left open.

The precedent that matters most is OPM's breach, where the tally of stolen federal fingerprints rose from 1.1M to 5.6M — proof that biometric compromise is measured in decades, not password-reset cycles. Biostar 2's exposure extends that class of loss to private-sector and policing infrastructure in Europe.

First-order effects

  • Banks, London police facilities, and defense contractors running Biostar 2 must now treat every enrolled fingerprint and face template as compromised, since biometrics cannot be reissued the way exposed credentials can.

Second-order effects

  • Supriya-style cloud-hosted access control becomes a procurement liability: enterprise and government buyers of biometric systems will demand on-premise or isolated deployments, forcing vendors like Suprema to rebuild trust through architecture rather than assurances.

Third-order effects

  • If the pattern holds — OPM's fingerprints, the Beijing system, this leak — regulators are likely to treat biometric templates as a special category demanding storage minimization and breach-specific rules, reshaping how physical-security and surveillance systems are allowed to centralize identity data.

The trend: Biometric identity infrastructure is scaling across banks, police, and defense faster than its storage security, turning access-control vendors into systemic single points of failure for irreplaceable personal data.

Discussion

  • @briankrebs @briankrebs on x
    Major #breach found in #biometrics system used by banks, UK police and defense firms https://www.theguardian.com/ ... Instead of saving a hash of the fingerprint, they reportedly stored the actual fingerprint. Biometrics firms should be held to a higher standard, IMHO. c/o @joshg…
  • @lessin Sam Lessin on x
    Oh man... the British better get ready to pay a several hundred billion dollar fine given recent benchmarks. That is gonna sting. pic.twitter.com/iwG0uXKPxe
  • @tomsamaki Tom Fisher on x
    Almost 30 million records left accessible and unencrypted, including images (not templates) of fingerprints. People affected should change their fingers immediately. You shouldn't use the same physical body for more than one service. #biometrics https://twitter.com/...
  • @kylerankin Kyle Rankin on x
    Ok everyone, time to reset your face and fingerprint. https://twitter.com/...
  • @axbom Per Axbom on x
    Use your fingerprint they said. It will be smooth they said. “Unlike passwords being leaked, when fingerprints are leaked, you can't change your fingerprint.” Yes, in this case the actual fingerprints were visible. There are millions of systems like it. https://www.theguardian.co…
  • @michaelgmadden Michael Madden on x
    If you are an affected customer, please change your password, fingerprints and face immediately. https://twitter.com/...