INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Oklahoma Department of Securities Leaked Millions of Sensitive Financial Files

| 2025-07-10 08:09 HIGH HIGH DATA BREACH
Executive Summary
AI-generated
In July 2018, a storage server belonging to the Oklahoma Department of Securities was found to be publicly accessible, exposing millions of files containing personal information, system credentials, and internal documentation. The data store was secured by UpGuard's Data Breach Research team on July 10, 2025, preventing potential malicious exploitation. The exposed data totalled three terabytes and consisted of files generated over decades, with the oldest dating back to 1986 and the most recent modified in 2016. This incident highlights a significant impact on the Oklahoma Department of Securities' network integrity due to the exposure of administrative and staff credentials.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

se•••••.gov
Id•••••.csv
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
WannaCryWannaCry
Target & Sectors
NORTH_AMERICA NORTH_AMERICA healthhealth
Incident Timeline
‎July 2015
Threat actors exploited vulnerabilities in email backups stored on the ok.gov domain, specifically securities.ok.gov, to leak millions of sensitive files containing personal data for over a hundred thousand brokers.
data_breach 16 GB
‎November 30th, 2018
Threat actors exploited the outdated IIS 6.0 web server, which reached end of life in July 2015, to target the Oklahoma Department of Securities website on November 30th, 2018.
infrastructure 6.0
Tactical Metrics
Metrics
infrastructure
‎6.0
Software Version
Metrics
data_breach
16
Gb