Rental giant Carla leaks user names, emails, and phone numbers ahead of summer holiday break


Car rental comparison and booking platform Carla kept a database with sensitive customer information unlocked on the open internet, freely available to anyone who knew where to look.

Cybersecurity researchers from Cybernews reported finding an exposed Amazon Web Services (AWS) bucket with approximately 48,000 PDF files. These files, which was later determined belonged to Carla, contained car rental details and drivers’ personal information.

Among other things, these files held vouchers and confirmation numbers, drivers’ names, email addresses, and phone numbers, rent periods, costs, pick-up and drop-off locations, as well as general vehicle information.

Read more…
Source:  Tech Radar news


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • London council warns residents’ data may have been compromised by cyber attack on healthcare provider

    May 22, 2024

    A London council has warned residents their personal data may have been compromised after a healthcare provider was hit by a cyber attack. The City of London Corporation said it is working with NRS Healthcare to understand the extent of the breach, and will be in contact with any residents whose information has been taken. The ...

  • Patriot Mobile Suffers Data Breach Impacting Subscriber’s Personal Data

    May 21, 2024

    U.S. mobile service provider Patriot Mobile fell victim to a security incident resulting in the leak of subscriber details including names, email addresses, zip codes, and account PINs, as reported by TechCrunch. The operator, Patriot Mobile, which boasts itself as a “Christian conservative wireless provider” with an estimated customer base under 100,000, has been seen endorsing ...

  • Western Sydney University staff, students caught in cyber attack

    May 21, 2024

    About 7500 staff and students have been caught up in a massive cyber attack at Western Sydney University. Police are investigating the breach, which the university says dates as far back as May 2023, when an unauthorised party got into the Microsoft Office system and accessed email accounts and SharePoint files. WSU says they have not ...

  • Medusa announced attack on John R. Wood Christie’s International Real Estate group

    May 20, 2024

    No patron information was compromised in a recent ransomware attack against John R. Wood Christie’s International Real Estate by a cyber gang known as Medusa, according to the company. Medusa announced the attack on its site, claiming it had stolen more than 1 terabyte of Wood data. The gang demanded $2 million from the real estate ...

  • Healthcare company WebTPA discloses breach affecting 2.5 million people

    May 17, 2024

    A Texas-based company that provides health insurance and benefit plans disclosed a data breach affecting almost 2.5 million people, some of whom had their Social Security number stolen. WebTPA said in a data breach notice published earlier this month that the company detected “evidence of suspicious activity” on December 28, 2023, which prompted the company to ...

  • Another cyber-attack on Australian healthcare company

    May 16, 2024

    here’s been another large-scale ransomware data breach of an Australian company…this time at an e-script provider named Medi-Secure. Medi-Secure is a prescription exchange service, which offers electronic prescribing and dispensing of prescriptions. It’s not yet known how many data records have been accessed, but experts warn that many Australians might not even know their details were ...