It's fascinating how these secrets are turning up in the press now. The article is (probably intentionally) vague about it's sources: they only say "Lighthouse found a vast archive of data on the deep web". But reading between the lines - does that imply that this surveillance company kept records on thousands of targets, and then left them in an open S3 bucket? Not the first time - the TM_Signal leak of upper-echelon U.S. government communications was also facilitated by an open S3 bucket that contained the message archives of everything that, say, the Secretary of Defense was messaging to the POTUS.
But it is highly ironic that these companies specialize in surveillance, tracking, and security, and then have a tendency to leave the data that they steal from others open to the Internet in a very amateurish security lapse that in turn leads to everyone stealing from them.