Reqrea, the Japan-based operator of the Tabiq hotel check-in platform, exposed sensitive identity documents for more than 1 million hotel guests after an Amazon cloud storage bucket named tabiq was left publicly accessible without authentication. The exposed files reportedly included passports, driver’s licenses, and selfie verification images used for facial-recognition-based hotel check-in, with records spanning from early 2020 through May 2026 and affecting guests from multiple countries.
Security researcher Anurag Sen discovered the exposure and alerted TechCrunch, which then notified Reqrea and Japan’s JPCERT; the bucket was secured after disclosure. Reqrea said it is investigating how the bucket became public, reviewing logs to determine whether unauthorized parties accessed the data, and plans to notify affected users once the scope of the incident is confirmed. The incident appears tied to a basic cloud misconfiguration rather than a sophisticated intrusion.

Map this exposure pattern across your cloud, code, and identities.
5 events from the most recent confirmed update back to the earliest known activity.
Reqrea said it is reviewing logs to determine the full scope of the exposure and whether anyone other than the researcher accessed the data. The company also said it plans to notify affected individuals once its investigation is complete.
Following notification, Reqrea restricted access to the misconfigured Amazon bucket, ending public exposure of the guest identity records. The company said it was still investigating how the bucket became public and whether any unauthorized access occurred.
After Sen's discovery, TechCrunch contacted Reqrea and Japan's JPCERT to report the publicly accessible bucket and the sensitive guest data exposure. This disclosure prompted the company to respond to the incident.
Independent researcher Anurag Sen found that Reqrea's Amazon cloud storage bucket named "tabiq" was publicly accessible without authentication, exposing more than one million customer identity records. The exposed data affected hotel guests from multiple countries using the Japan-based Tabiq check-in platform.
Files in Reqrea's publicly exposed Amazon S3 bucket dated back to early 2020, indicating the Tabiq hotel check-in platform had been storing sensitive guest identity documents there from at least that time. The data included passports, driver's licenses, and selfie verification images used for hotel check-in.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.