INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Oklahoma Department of Securities Leaked Millions of Files Online
| 2025-07-10 08:09 HIGH HIGH DATA BREACH
Executive Summary
AI-generated
In July 2018, a storage server belonging to the Oklahoma Department of Securities was found to be publicly accessible, exposing millions of files containing personal information, system credentials, and internal documentation. The data store was secured by UpGuard's Data Breach Research team on July 10, 2025, preventing potential malicious exploitation. The exposed data totalled three terabytes and consisted of files from the 1980s to 2016, with an estimated hundreds of millions of files. The attack worked through an unsecured rsync service at an IP address registered to the Oklahoma Office of Management and Enterprise Services, allowing anyone to download all files on the server. As a result, the Oklahoma Securities Commission's website now has a Cyber Risk score of 171 out of 950, indicating severe risk of breach due to outdated web servers and unpatched vulnerabilities.
Technical Mitigations AI-generated
• Patch IIS 6.0 to address newly discovered vulnerabilities, as it has reached end of life and no updates have been released in the last three and a half years.
• Block or hunt for rsync service at IP addresses registered to the Oklahoma Office of Management and Enterprise Services, which allowed public access to sensitive data.
• Use Shodan search engine to monitor internet-facing IP addresses for potential security risks.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
se•••••.gov
Id•••••.csv
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
WannaCryWannaCry
Target & Sectors
Global Scope
healthhealth
Incident Timeline
July 2015
Threat actors gained unauthorized access to the Oklahoma Department of Securities' email backups, exposing millions of sensitive files.
Click on any entity below to view its context and source!
data_breach
16 GB
In the case of the OK Securities Commission exposure, email backups from 1999 to 2016 were present, with the largest and most recent reaching 16GB in size.
November 30th, 2018
Threat actors exploited the outdated IIS 6.0 web server, which reached end of life in July 2015, to target the Oklahoma Department of Securities' website and leak millions of files on November 30th, 2018.
Click on any entity below to view its context and source!
infrastructure
6.0
Among the issues lowering the website’s score is the use of the web server
IIS 6.0, which reached end of life in July 2015,
meaning no updates to address any newly discovered
vulnerabilities
have been released in the last three and a half years.
Tactical Metrics
Metrics
infrastructure
6.0
Software Version
Click for context!
Among the issues lowering the website’s score is the use of the web server
IIS 6.0, which reached end of life in July 2015,
meaning no updates to address any newly discovered
vulnerabilities
have been released in the last three and a half years.
Metrics
data_breach
16
Gb
In the case of the OK Securities Commission exposure, email backups from 1999 to 2016 were present, with the largest and most recent reaching 16GB in size.
Intelligence Sources
Upguard
2025-07-10
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:03
Comprehensive Tactical Telemetry
Highly Correlated Entities
28x
organisation
Identified Entity
PII
entity
6x
timeline
Temporal Reference
November 30th, 2018
date
2x
tactic
Cyber Operation Type
Data Breach
tactic
Contextual Telemetry
Context Block
8 METRICS
source region
Origin Country
United States
country
malware
Malware Payload
WannaCry
tool
general metric
Tier
1
tier
infrastructure
Software Version
6.0
version
general metric
Iis
6
iis
data breach
Gb
16
gb
tactic
MITRE ATT&CK Technique
T1589.001 - Credentials
technique
attribution
Attributing Entity
FBI
authority
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.