By Sead Fadilpašić
Copyright techradar
Skip to main content
Tech Radar Pro
Tech Radar Gaming
Close main menu
the business technology experts
België (Nederlands)
Deutschland
North America
US (English)
Australasia
New Zealand
View Profile
Search TechRadar
Expert Insights
Website builders
Web hosting
Best web hosting
Best office chairs
Best website builder
Best antivirus
Expert Insights
Don’t miss these
Nearly 250,000 records leaked in major tax consultancy breach – here’s what we know
Massive database containing identity info on 252 million people leaked online – here’s what we know
Insurance firm AIL allegedly hit in cyberattack – hackers claim info on over 150,000 users stolen, here’s what we know
Over 1 million records from US adoption organization left exposed online
Major breach sees 100 million data records on citizens leaked – here’s what we know
Allianz Life data leaked following recent breach – our tips on how to stay safe
Insurance giant Allianz Life says data on over a million US customers stolen in breach – here’s how to stay protected
This major cybercrime forum might have just exposed all its users
Over 26 million resumes exposed in top CV maker data breach – here’s what we know
Largest US credit union leaked potentially sensitive information
Insurance group Kelly Benefits says over half a million people now affected in major data breach – here’s what we know
Allianz Life breach now thought to have affected 1.1 million customers – here’s how to stay safe
Farmers Insurance data breach sees over a million customers hit – here’s what we know
Hackers claim to be selling 61 million Verizon records online, but it might not be what it seems
Top VC firm is warning thousands their data may have been hacked – here’s how to stay safe
Top auto insurance firm leaked over 5 million records – here’s what we know
Sead Fadilpašić
24 September 2025
ClaimPix kept an open database online, experts say
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
(Image credit: Pixabay)
ClaimPix exposed 5.1 million sensitive insurance files on an unsecured public database
Documents included personal data, vehicle details, and internal company records
ClaimPix restricted access and pledged code updates after researcher alerted them
ClaimPix, a company which streamlines car insurance claims, was leaking sensitive customer data on the clearweb, including people’s phone numbers, and email addresses, an expert has warned.
Security researcher Jeremiah Fowler, known for hunting down misconfigured and unprotected databases, recently found one such instance containing 5.1 million files, sharing his findings with WebsitePlanet.
The archive was 10TB in size, and included documents such as power of attorney, vehicle registration, estimates, repair invoices, and images of damaged vehicles with visible license plates and VIN numbers.
You may like
Nearly 250,000 records leaked in major tax consultancy breach – here’s what we know
Massive database containing identity info on 252 million people leaked online – here’s what we know
Insurance firm AIL allegedly hit in cyberattack – hackers claim info on over 150,000 users stolen, here’s what we know
ClaimPix leaks
The data also included insurance documents with names, postal addresses, phone numbers, and emails, and registration documents with additional details about vehicles, but also internal documents with terms, fees, and other information that should not be available to the general public.
Fowler’s investigation led him to ClaimPix, a Hillside, Illinois technology company providing a self-service photo documentation platform to streamline insurance claims, damage assessments, and remote inspections. It covers multiple industries including insurance, car shipping, and contracting.
ClaimPix is a relatively small, privately-held organization, that operates with fewer than 25 employees, and generates roughly $5 million in annual revenue. According to some sources, it processed more than 25,000 claims across the United States, and built partnerships with firms like Bluestar Corporate Relocation.
Soon after Fowler reached out, the company restricted the database from public access, and apologized for the mishap.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsorsBy submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
“We have updated policies and our code to address this issue and will be making those changes live later this evening,” ClaimPix told the researcher.
A few details remain unknown: we don’t know if ClaimPix operates this archive, or if the work is outsourced to a third party. We also don’t know for how long it remained open, and if any threat actors accessed it before it was locked down. At press time, there was no evidence that the files were stolen or abused in phishing attacks.
You might also like
Data center firm leaks massive 38GB database containing thousands of personal records online
Take a look at our guide to the best authenticator app
We’ve rounded up the best password managers
Sead Fadilpašić
Social Links Navigation
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.
Nearly 250,000 records leaked in major tax consultancy breach – here’s what we know
Massive database containing identity info on 252 million people leaked online – here’s what we know
Insurance firm AIL allegedly hit in cyberattack – hackers claim info on over 150,000 users stolen, here’s what we know
Over 1 million records from US adoption organization left exposed online
Major breach sees 100 million data records on citizens leaked – here’s what we know
Allianz Life data leaked following recent breach – our tips on how to stay safe
Latest in Security
GitHub is finally tightening up security around npm following multiple attacks
Watch out – even small businesses are now facing threats from deepfake attacks
“It could be catastrophic to the city” – US Secret Service takes down massive million-dollar network of SIM cards it says was capable of taking down comms across New York
US federal agency breached by hackers using GeoServer exploit, CISA says
Insurance firm AIL allegedly hit in cyberattack – hackers claim info on over 150,000 users stolen, here’s what we know
Huge theft reportedly sees 2TB of private data stolen – police files hit in major breach
Latest in News
New Stranger Things season 5 trailer teases one last quest for the Hawkins crew – and lots of unseen footage for the hit Netflix show’s final hurrah
Proton VPN’s no-logs policy holds up under scrutiny of fourth independent audit
Fears of the death of Intel Arc GPUs may be exaggerated – despite Nvidia deal, a powerful new graphics card is rumored
What is the release date for Peacemaker season 2 episode 6 on HBO Max and other streaming services?
Two annoying Windows 11 bugs have finally been fixed – and it only took Microsoft a year
WhatsApp users have been begging for message translations for two long years – and now it’s finally here
LATEST ARTICLES
‘That element of the show really captured my mind’ – forget Xenomorphs, Alien: Earth’s cast say the real story is something even darker
US federal agency breached by hackers using GeoServer exploit, CISA says
New Stranger Things season 5 trailer teases one last quest for the Hawkins crew – and lots of unseen footage for the hit Netflix show’s final hurrah
GitHub is finally tightening up security around npm following multiple attacks
Quordle hints and answers for Thursday, September 25 (game #1340)
TechRadar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.
Contact Future’s experts
Terms and conditions
Privacy policy
Cookies policy
Advertise with us
Web notifications
Accessibility Statement
Future US, Inc. Full 7th Floor, 130 West 42nd Street,
Please login or signup to comment
Please wait…