INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Oklahoma Department of Securities Leaked Millions of Files Online

| 2025-07-10 08:09 HIGH HIGH DATA BREACH
Executive Summary
AI-generated
In July 2018, a storage server belonging to the Oklahoma Department of Securities was found to be publicly accessible, exposing millions of files containing personal information, system credentials, and internal documentation. The data store was secured by UpGuard's Data Breach Research team on July 10, 2025, preventing potential malicious exploitation. The exposed data totalled three terabytes and consisted of files from the 1980s to 2016, with an estimated hundreds of millions of files. The attack worked through an unsecured rsync service at an IP address registered to the Oklahoma Office of Management and Enterprise Services, allowing anyone to download all files on the server. As a result, the Oklahoma Securities Commission's website now has a Cyber Risk score of 171 out of 950, indicating severe risk of breach due to outdated web servers and unpatched vulnerabilities.
Technical Mitigations AI-generated
• Patch IIS 6.0 to address newly discovered vulnerabilities, as it has reached end of life and no updates have been released in the last three and a half years. • Block or hunt for rsync service at IP addresses registered to the Oklahoma Office of Management and Enterprise Services, which allowed public access to sensitive data. • Use Shodan search engine to monitor internet-facing IP addresses for potential security risks.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

se•••••.gov
Id•••••.csv
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
WannaCryWannaCry
Target & Sectors
Global Scope healthhealth
Incident Timeline
‎July 2015
Threat actors gained unauthorized access to the Oklahoma Department of Securities' email backups, exposing millions of sensitive files.
data_breach 16 GB
‎November 30th, 2018
Threat actors exploited the outdated IIS 6.0 web server, which reached end of life in July 2015, to target the Oklahoma Department of Securities' website and leak millions of files on November 30th, 2018.
infrastructure 6.0
Tactical Metrics
Metrics
infrastructure
​6.0
Software Version
Metrics
data_breach
16
Gb