Sensitive plastic surgery photos exposed online

Hundreds of thousands of records belonging to plastic surgery patients have been discovered sitting on an unprotected server for anyone to view…
plastic surgery

Share this article:

Hundreds of thousands of records belonging to plastic surgery patients have been discovered sitting on an unprotected server and accessible for anyone to view. The data were stored on an Amazon Web Services (AWS) S3 bucket database belonging to NextMotion, a plastic surgery technology company that provides imaging solutions to clinics around the world.

Researchers at vpnMentor, who uncovered the leak, were able to access some 900,000 individual records. These ranged from before-and-after images and videos of cosmetic procedures to materials of a highly sensitive nature, including graphic photos of the patients’ private body parts. The origin of the records is not clear but it can be assumed that the leak affected NextMotion clients.

Besides patient facial and body photos, the trove of information included invoices, outlines of proposed treatments, and video files including 360-degree face and body scans. The invoices detailed the medical procedures, their costs, dates when they were performed, and personal information that could help identify patients.

All things considered; the data could allow hackers with malicious intent to create a comprehensive portrait of their potential victims. The patients could then easily become targets of identity theft, phishing, financial fraud or even sextortion, where criminals use intimate material to demand a ransom.

NextMotion CEO Dr Emmanuel Elard apologised, adding that the issue has been addressed: “Amazon Web Service warned us on the January 30. After internal discussions with Amazon’s support, we immediately took corrective steps on the February 4. The cybersecurity company formally guaranteed that the security flaw had completely disappeared.”

As NextMotion is headquartered in France and offers services in the European Union (EU), it is subject to the EU’s General Data Protection Regulation (GDPR). Although the company’s website states that its technology is GDPR certified, the failure to secure patients’ sensitive data may carry stiff penalties and legal actions.

Misconfigured and unsecured public-facing data repositories have become a common occurrence. In one recent case, thousands of birth certificate applications were stored unprotected on an AWS cloud platform, while another data leak affected almost all of Ecuador’s citizens. These leaks were unintentional, but there have been cases where cosmetic surgery clinics, such as a well-known clinic in London, were targeted by cybercriminals.

For more security news visit here.

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Ai Solution of the year - securitybuyer.com

Have your say: vote for AI Solution of the Year

Voting is open for AI Solution of the Year at the Security Buyer Readers’ Awards 2026, with readers invited to select their winner
Access control of the year - securitybuyer.com

Have you voted for Access Control Solution of the Year?

Voting is open for Access Control Solution of the Year at the Security Buyer Readers’ Awards 2026, with readers invited
PaxLock Pro2 - securitybuyer.com

Paxton officially launches PaxLock Pro2

Paxton the security technology manufacturer has launched a brand-new re-engineered PaxLock which is built to protect straight
KentixONE data centre - securitybuyer.com

Data centre security with KentixONE

Prior1 develops container data centers to meet the highest security and energy efficiency standards. Their containers require
Chubbsafes - securitybuyer.com

Chubbsafes explores certified storage for jewellery and precious metals

Chubbsafes, part of Gunnebo Safe Storage, has launched a new technical discussion guide examining when certified
Mercury trends report - securitybuyer.com

New Mercury Research Finds Growing Cybersecurity Gap

2026 Trends in Access Controllers Report finds interoperability, cloud connectivity and AI are reshaping long-term controller strategies.
Chris Carroll - securitybuyer.com

Comelit-PAC Promotes Chris Carroll as Sales Director

Comelit-PAC has appointed Chris Carroll as Sales Director, following an 18 year career with the company, seeing him progress
Jason Bezuidenhout - securitybuyer.com

Zygal Appoints Jason Bezuidenhout

Zygal has appointed Jason Bezuidenhout as Chief Revenue Officer (CRO), strengthening its leadership team as the company continues
Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
Scroll to Top