Rental giant Carla leaks user names, emails, and phone numbers ahead of summer holiday break

https://cdn.mos.cms.futurecdn.net/GcQXTy4NBXKeoop4V5WQnQ-970-80.jpg
  • Cybernews found Carla’s exposed AWS bucket with 48,000 PDFs containing customer rental data
  • Files included names, emails, phone numbers, rental details, and travel patterns useful for phishing
  • Carla secured the database after disclosure; no evidence of malicious access, but risk remains

Car rental comparison and booking platform Carla kept a database with sensitive customer information unlocked on the open internet, freely available to anyone who knew where to look.

Cybersecurity researchers fromCybernewsreported finding an exposed Amazon Web Services (AWS) bucket with approximately 48,000 PDF files. These files, which was later determined belonged to Carla, contained car rental details and drivers’ personal information.

Among other things, these files held vouchers and confirmation numbers, drivers’ names, email addresses, and phone numbers, rent periods, costs, pick-up and drop-off locations, as well as general vehicle information.

Carla reacts

Cybernews says the data could have been used in convincing phishing attacks. Not only...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more