Rental giant Carla leaks user names, emails, and phone numbers ahead of summer holiday break


Car rental comparison and booking platform Carla kept a database with sensitive customer information unlocked on the open internet, freely available to anyone who knew where to look.

Cybersecurity researchers from Cybernews reported finding an exposed Amazon Web Services (AWS) bucket with approximately 48,000 PDF files. These files, which was later determined belonged to Carla, contained car rental details and drivers’ personal information.

Among other things, these files held vouchers and confirmation numbers, drivers’ names, email addresses, and phone numbers, rent periods, costs, pick-up and drop-off locations, as well as general vehicle information.

Read more…
Source:  Tech Radar news


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • News agency AFP notifies French authorities of potential data breach

    October 2, 2024

    Agence France-Presse (AFP), one of the world’s largest news organizations, has notified French regulators of a potential data breach following a cyberattack last week. The AFP, which has an editorial presence in 260 cities across 150 countries, said in a brief statement on Saturday that it detected an “attack on its systems” that affected part of ...

  • Dutch police leak leaves data of 62,000 officers in hands of hackers

    September 30, 2024

    Police are continuing to investigate the impact of a data leak last week in which hackers obtained the “work-related contact data of all police officers”. The Dutch national police force employs some 62,000 officers. According to an email sent to staff at the weekend, police chief Janny Knol an “office account” was hacked revealing names, email ...

  • Ireland fines Meta 91 mn euros over EU data breach

    September 27, 2024

    An Irish regulator helping to police European Union data privacy said Friday it had fined Facebook-owner Meta 91 million euros ($102 million) for password-security breaches. The Data Protection Commission criticised Meta for failing to put in place appropriate security measures to protect users’ password data and for taking too long to alert the regulator over the ...

  • UK data watchdog investigating MoneyGram data breach

    September 27, 2024

    The U.K.’s data protection regulator has confirmed it’s investigating MoneyGram after receiving a data breach report from the U.S.-based money transfer giant. The U.K.’s Information Commissioner’s Office, which requires that organizations report data breaches within 72 hours of discovering the incident, confirmed to TechCrunch on Friday that the watchdog had received a report from MoneyGram following ...

  • Australia’s biggest medical imaging provider I-MED data breach exposes tens of thousands of patient files

    September 26, 2024

    Tens of thousands of patients from Australia’s biggest medical imaging provider I-MED have had swaths of sensitive health and personal information exposed in a data breach using details that have been public for a year. This information includes medical reports, scan images, names, addresses and other details that were stored in I-MED’s internal systems, which were ...

  • 100 million+ US citizens have records leaked by background check service

    September 23, 2024

    A background check left a huge database unprotected online containing 2.2TB of people’s data, according to research by Cybernews. The database was left passwordless and easily accessible to anyone on the internet by background check firm MC2 Data. MC2 Data gathers publicly available data to provide decision makers with information whether someone can rent a house, ...