INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Oklahoma Department of Securities Leaked Millions of Sensitive Financial Files
| 2025-07-10 08:09 HIGH HIGH DATA BREACH
Executive Summary
AI-generated
In July 2018, a storage server belonging to the Oklahoma Department of Securities was found to be publicly accessible, exposing millions of files containing personal information, system credentials, and internal documentation. The data store was secured by UpGuard's Data Breach Research team on July 10, 2025, preventing potential malicious exploitation. The exposed data totalled three terabytes and consisted of files generated over decades, with the oldest dating back to 1986 and the most recent modified in 2016. This incident highlights a significant impact on the Oklahoma Department of Securities' network integrity due to the exposure of administrative and staff credentials.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
se•••••.gov
Id•••••.csv
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
WannaCryWannaCry
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
healthhealth
Incident Timeline
July 2015
Threat actors exploited vulnerabilities in email backups stored on the ok.gov domain, specifically securities.ok.gov, to leak millions of sensitive files containing personal data for over a hundred thousand brokers.
Click on any entity below to view its context and source!
data_breach
16 GB
In the case of the OK Securities Commission exposure, email backups from 1999 to 2016 were present, with the largest and most recent reaching 16GB in size.
November 30th, 2018
Threat actors exploited the outdated IIS 6.0 web server, which reached end of life in July 2015, to target the Oklahoma Department of Securities website on November 30th, 2018.
Click on any entity below to view its context and source!
infrastructure
6.0
Among the issues lowering the website’s score is the use of the web server
IIS 6.0, which reached end of life in July 2015,
meaning no updates to address any newly discovered
vulnerabilities
have been released in the last three and a half years.
Tactical Metrics
Metrics
infrastructure
6.0
Software Version
Click for context!
Among the issues lowering the website’s score is the use of the web server
IIS 6.0, which reached end of life in July 2015,
meaning no updates to address any newly discovered
vulnerabilities
have been released in the last three and a half years.
Metrics
data_breach
16
Gb
In the case of the OK Securities Commission exposure, email backups from 1999 to 2016 were present, with the largest and most recent reaching 16GB in size.
Intelligence Sources
Upguard
2025-07-10
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:27
Comprehensive Tactical Telemetry
Highly Correlated Entities
28x
organisation
Identified Entity
PII
entity
6x
timeline
Temporal Reference
November 30th, 2018
date
2x
tactic
Cyber Operation Type
Data Breach
tactic
Contextual Telemetry
Context Block
8 METRICS
target region
Target Country
United States
country
malware
Malware Payload
WannaCry
tool
general metric
Tier
1
tier
infrastructure
Software Version
6.0
version
general metric
Iis
6
iis
data breach
Gb
16
gb
tactic
MITRE ATT&CK Technique
T1589.001 - Credentials
technique
attribution
Attributing Entity
FBI
authority
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.