Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Deep Root Analytics Is in Deep Trouble With Voter Data Breach

by The Gurus
June 29, 2017
in Editor's News
Data Breach Cyber attack code
Share on FacebookShare on Twitter

Cybersecurity experts speculate that in our current state, up to 70% of cyber attacks, including breaches, go undetected in a given year. Part of identifying and stopping breaches is knowing what kind of information cybercriminals are after, and election season creates hotbeds of public information that are prime targets for a breach.
The companies that house this information are, of course, responsible for keeping your data protected, but things don’t always go according to plan. Case in point: During the 2016 election season, GOP analytics firm Deep Root Analytics left the door wide open for crooks to access 198 million Americans’ voting information.
Politicians Prosper, Voters Are Exposed
Deep Root was hired to gather the information to support what would become the successful 2016 GOP presidential campaign. It included names, birthdays, phone numbers, voting information and even home addresses.
The company stored all this information on a database which researcher Chris Vickery discovered was misconfigured. The error meant there was no access protection for the database. Anyone with an internet connection could view and potentially steal the personal information of nearly 2 million Americans.
The database also included modelled positions, strategic information used by the GOP to market its campaign to voters. Had a major retailer allowed this type of information about their customers to get out, it probably would have been all over the news. Thankfully, it appears that while the door was left open, there were no nefarious attempts to access the data made during the 12 days it was unprotected.
Deep Root Responds to the Breach
With the number of cybersecurity issues surrounding the 2016 election year already staggering, Deep Root has taken a transparent stance toward the information leak. In a statement, the company encourages voters to monitor their accounts for fraudulent activity. They also attempt to temper the blow by pointing out that much of this info is public domain in some states.
Presumably, not all of Deep Root’s customers are political parties, and the field of data analytics is growing rapidly. In a business setting, critical analysis of data not unlike what Deep Root gathered can help businesses decrease operating costs by 60 percent or more. That’s a service you can charge for, and chances are Deep Root doesn’t want to forfeit any more customers than it has to in the wake of such a major error.
To remedy the exposed database, Deep Root updated access settings to the information, adding the layers of security that should have been in place to begin with.
White Hat Probing Uncovered the Error
While it might sting a little now, Deep Root is fortunate that consultancy firm UpGuard was around to point out the issue. Had it been left unattended to, there’s no telling where the information could wind up. Probably on the dark web, just like the Yahoo account information that has been up for sale there for half a year now.
Chris Vickery, the man who located the flaw in Deep Root’s system, is just one of many researchers engaged in locating and reporting these types of errors every day. While you might not hear about them, they play a critical role in ensuring the security of your data.
Google’s Project Zero is one such operation, a dedicated department of the 800-pound internet gorilla focused solely on uncovering vulnerabilities and thinking like cybercriminals. Their goal is to find the flaws before bad guys get there, and oftentimes they do. When an issue is found, the Project Zero coders report it to the organization responsible so they can apply a patch or remove the vulnerability.
Is Privacy a Reasonable Expectation Anymore?
Can the efforts of these good-guy hackers ever fully curtail the leak of information that has been gushing out of the internet since, well, probably before we even know?
Maybe not, but through careful regulation and fastidious maintenance, we can patch the easy holes. Deep Root got lucky — it committed a blatant error and wasn’t punished for it.
Just like burglary, data breaches are nearly always a crime of opportunity. If you leave the front door wide open, you had better expect someone to come waltzing in.

Tags: BreachCyberdatasecurityTechnology
ShareTweet
Previous Post

Community Led Threat Prevention

Next Post

Report: 70% of brits unable to tell fact from fiction, share fake news

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol