A taxi software company was discovered to have exposed the personal details of around 300,00 customers in the UK and Ireland.
The data exposure occurred due to a non-password protected database – personal details, including names, email addresses, and mobile numbers were left unsecure.
22,745 records and documents containing personal information, including user IDs, were in the exposed dataset from iCabbi, taxi software firm based in Ireland.
According to Jeremiah Fowler, who first discovered and reported the database, the exposed email addresses were from a range of providers and private domains, including: 117,231 Gmail, 65,060 Hotmail, 17,588 Yahoo, 18,099 iCloud, 12,798 Outlook, 7,484 Live, as well as others.
Intriguingly, Fowler also discovered email addresses from major media outlines like the BBC, as well as government agencies such as the NIH, HM Treasury, and Ministry of Justice. University email addresses were also included in the findings.
The database seemed to be a content management storage repository, according to Fowler, used for terms and conditions documents as well as customer data spreadsheets.
Within the folder, however, were other documents that were secured and could not be accessed publicly.
Recommended reading
- UK Gov to Link China to Electoral Commission Cyber-attack
- NCSC Releases Cyber Incident Response Guidance for CEOs
- Over 1 in 10 Business Leaders Don’t Know if They’ve Been Hacked
“The potential risk of cyber criminals knowing the file paths of where documents are stored could allow a targeted brute force attack against the wider network or identifying individual misconfigured documents. I am not saying iCabbi’s network was at imminent risk, but I am providing a hypothetical risk of exposing the file path where customer documents are collected and stored,” Fowler wrote for vpnMentor.
iCabbi has since responded to the disclosure notice, saying: “Thanks again for bringing this to my attention – we have deleted the records. Human error to blame here unfortunately… part of a migration of customers but we should not be using public folders. We are going to engage with customers to make them aware of this breach” as reported by vpnMentor.





