The Challenge
On June 8, 2017, UpGuard's Cyber Risk Team discovered a publicly accessible Amazon Web Services S3 bucket containing Verizon customer data, names, addresses, account details, and account PINs for up to 14 million US customers. This repository wasn't owned by Verizon but by NICE Systems, a third-party vendor providing call center and workforce management software.
The bucket, labeled "verizon-sftp," contained automated daily logs from January to June 2017. While most call records had sensitive fields masked, some did not. One text file exposed 6,000 unmasked PIN codes with phone numbers and account details. Anyone with the S3 URL could download the entire repository.
The technical failure was clear: misconfigured cloud storage permissions. The governance failure was harder to diagnose. NICE Systems, an Israeli firm acquired by Verizon partners inContact and VPI in 2016, had become a trusted part of Verizon's infrastructure. Few customers knew their data was processed by this vendor, let alone logged offshore in Ra'anana, Israel.
The Environment and Constraints
NICE Systems provided voice analytics and workforce management technology crucial to Verizon's call center operations. SEC filings identified Verizon as a "main partner." This relationship was deeply integrated into daily customer service workflows.
The exposed data reflected this integration. Log files included voice recognition transcripts from Verizon's customer support line, with fields like "TimeInQueue" and "FrustrationLevel." The system's real-time operational use was confirmed by pings to subdomains of voiceportalfh.verizon.com.
The repository also contained French-language data from Orange S.A., another NICE Systems client and Verizon competitor in Europe. This raised questions about logical segregation controls within NICE's infrastructure.
Verizon faced a common challenge for large enterprises: as operational integration deepens, visibility into vendor data handling practices erodes. Verizon relied on NICE's technology daily but lacked real-time awareness of data storage locations, access controls, and logging practices.
The Approach Taken
UpGuard notified Verizon on June 13, 2017. The S3 bucket remained publicly accessible until June 22, nine days later. The repository's logging folders show activity halting on that date, indicating remediation occurred only after sustained external pressure.
Neither Verizon nor NICE Systems disclosed specific remediation steps. The bucket was eventually secured, preventing further access. Verizon's spokesperson later disputed the exposure scale, claiming only six million customers were affected, not UpGuard's estimate of 14 million.
The response timeline suggests a coordination problem. Verizon didn't own the infrastructure. NICE Systems, operating from Israel with multinational clients, may have had competing priorities or unclear escalation protocols. The nine-day window between notification and closure reflects what happens when contractual controls don't translate into operational urgency.
Results and Metrics
The breach was contained without reported exploitation. No public disclosures indicate that the exposed PIN codes were used for account takeovers or SIM swap fraud, though the absence of evidence isn't evidence of absence.
The exposure highlighted a vulnerability in two-factor authentication architectures. As The Verge noted, wireless carriers represent a weak point in 2FA systems. If you compromise the carrier account supporting a phone number, you can hijack calls and texts used for authentication. The combination of account PINs, phone numbers, and fields like "CallCenterPassword" created a roadmap for targeted social engineering.
The incident also revealed gaps in vendor data governance. NICE Systems had created a logging repository for "unknown purposes," per UpGuard's analysis. Verizon either didn't know the repository existed or hadn't validated its access controls. The presence of Orange S.A. data in the same bucket suggested NICE's internal segregation practices were inadequate for a multi-tenant environment handling competitor data.
What They Would Do Differently
The nine-day closure window points to missing contractual mechanisms. Effective vendor arrangements include:
Notification timelines tied to data classification. If the contract had required NICE Systems to remediate critical exposures within 24 hours of notification, the response would have been faster. Instead, the timeline suggests ad hoc coordination.
Right to Audit clauses covering cloud infrastructure. Verizon needed visibility into how NICE Systems configured AWS resources, not just assurances of security practices. Audit rights should extend to infrastructure-as-code templates, IAM policies, and bucket-level permissions.
Sub-Outsourcing Clauses requiring pre-approval for offshore data storage. The Ra'anana-based repository suggests Verizon didn't know where its customer data was being logged or didn't have contractual authority to restrict it. Data residency requirements should be explicit and enforceable.
Automated continuous monitoring of vendor-controlled infrastructure. Waiting for an external researcher to discover the exposure meant Verizon had no independent validation of NICE's security posture. Cyber risk ratings and attack surface monitoring tools can identify misconfigured S3 buckets before they're weaponized.
NICE Systems should have implemented least-privilege access controls and automated compliance checks. AWS Config rules can flag publicly accessible S3 buckets in real time. The fact that the repository remained open for months suggests these controls weren't deployed.
Takeaways for Your Team
Map data flows before they become incidents. If you can't diagram where your vendor stores your data, you can't assess the risk. Pre-contractual assessments should include infrastructure architecture reviews, especially for vendors with embedded operational roles.
Tier vendors by data exposure, not just business criticality. NICE Systems may not have been a Tier 1 vendor by revenue, but it had access to 14 million customer records. Criticality Classification should weight data sensitivity alongside operational impact.
Contractual audit rights are worthless without exercise cadence. Schedule annual infrastructure audits for vendors handling sensitive data. Review IAM policies, encryption configurations, and logging practices, not just SOC 2 attestations.
Incident Escalation protocols must account for cross-border vendors. Nine days is unacceptable for a critical data exposure. Your contract should specify escalation paths, remediation SLAs, and financial penalties for non-compliance.
Continuous monitoring extends to vendor infrastructure. Deploy tools that scan for exposed cloud storage, leaked credentials, and misconfigured APIs across your vendor ecosystem. External discovery shouldn't be your first alert.
The Verizon-NICE Systems incident wasn't a sophisticated attack. It was a misconfigured S3 bucket that stayed open because contractual controls didn't translate into operational accountability. Your vendor relationships are only as secure as your ability to verify their configurations and enforce your standards when they fail.





