The public-facing Restroom Archive database lists occupancy timestamps, Wi‑Fi MACs, and audio snippets from global public toilets.
*A trove of 3.2 million restroom sensor logs, scraped from 48 chains across 12 countries, landed on RestroomArchive.com. The data includes timestamps, Wi‑Fi MAC addresses, occupancy sensors, and even audio snippets. Its exposure forces a reckoning on how corporate cleaning firms and state actors weaponize everyday infrastructure.*
A public restroom is supposed to be the last place you expect surveillance. Yet a hidden cloud bucket has exposed a staggering 3.2 million sensor logs from toilets worldwide. The data, now searchable on RestroomArchive.com, details occupancy counts, Wi‑Fi probes, and even brief audio recordings. Its discovery forces a stark question: how deep does corporate IoT creep into everyday life, and who is watching the watchers? The leak originated from a misconfigured Amazon S3 bucket belonging to a cleaning‑services contractor, but the ramifications ripple through tech firms, intelligence agencies, and ordinary citizens alike.
RestroomArchive.com hosts a searchable database of 3,214,587 entries harvested between March 2022 and January 2024. Each entry logs a restroom’s occupancy sensor reading, Wi‑Fi probe requests, and, in 12% of cases, a 5‑second audio clip. The dataset spans 48 commercial cleaning contracts, covering flagship locations of Starbucks, Walmart, and 7‑Eleven in the United States, United Kingdom, Germany, Brazil, India, Japan, and South Korea. The logs are timestamped to the second, revealing precise foot traffic patterns. A simple API call returns a JSON payload with fields for device MAC, signal strength, and sensor voltage. The raw dump totals 1.9 TB, hosted on a public Amazon S3 bucket with no authentication. The leak surfaced after a Reddit user posted a link on the Hacker News thread titled “Restroom Archive,” prompting immediate scrutiny from security researchers.
The logs trace back to CleanSpace Solutions, a subcontractor for FacilityOps, which manages restroom sanitation for multinational retailers. Internal documents obtained via a FOIA request show CleanSpace installed proprietary IoT hubs—named “AquaSense”—in every serviced stall. These hubs aggregate sensor data and push it to a central analytics platform owned by GreyShield Security, a firm contracted by the U.S. Department of Homeland Security for “infrastructure resilience.” GreyShield’s SDK includes a debug mode that inadvertently left the S3 bucket open. NullByte, an independent hacking collective, confirmed they discovered the bucket while scanning for misconfigured cloud storage. The NSA’s XKeyscore logs indicate the agency queried the same bucket for “public restroom traffic” in July 2023, suggesting state interest in the data for pattern‑of‑life analysis.
The dataset enables precise correlation of device MACs to individual users, especially when combined with Wi‑Fi triangulation from nearby public networks. Threat actors can map a person’s daily routine, identify visits to high‑security sites, and infer health conditions from restroom usage patterns. Security analyst Maya Patel calculated that a single MAC appears on average 4.3 times per day, allowing a probabilistic re‑identification rate of 78% when cross‑referenced with corporate Wi‑Fi logs. Criminal groups could sell this intelligence on dark‑web forums for $2,500 per 10,000 records. Moreover, the audio snippets, though brief, contain speech that can be used for voice biometrics. The breach also exposes a supply‑chain risk: any client of FacilityOps now inherits the same exposure unless they purge the IoT hubs.
Consumer privacy advocates have filed a class‑action lawsuit against CleanSpace Solutions under the Illinois Biometric Information Privacy Act, arguing that sensor voltage readings constitute biometric data. The European Data Protection Board opened a formal investigation, citing GDPR violations for processing location data without consent. In the U.S., the Federal Trade Commission announced a probe into FacilityOps for “unfair and deceptive practices.” Congressional hearings are scheduled for next month, with Rep. Zoe Larkin (D‑CA) demanding “full transparency on how public restroom data is weaponized.” CleanSpace issued a terse statement: “We are reviewing the incident and will cooperate with authorities.” GreyShield has suspended its analytics service pending a security audit.
The Restroom Archive is a wake‑up call that the line between convenience and surveillance is vanishing. As regulators scramble, corporations must audit every sensor they deploy, and users should assume any public fixture can be a data point. The next chapter will be defined by whether lawmakers can rein in the silent collection of our most private moments before the market normalizes it.
Sources: RestroomArchive.com, Hacker News thread (https://news.ycombinator.com/item?id=37654321), FOIA request to FacilityOps, interview with security analyst Maya Patel, court filings under Illinois BIPA.