An unencrypted AWS cloud storage bucket managed by student transit provider GET was left exposed to the clear web. The asset leaked sensitive student profiles, digital card identifiers, transit tracking records, and system verification codes across multiple domestic institutions.