Site navigation

300k UK&I Data Records Exposed in Taxi Software Leak

Elizabeth Greenberg

,

taxi data leak
Personal data, such as emails, names, and phone numbers, were left exposed to the public due to poor cyber due-diligence. 

A taxi software company was discovered to have exposed the personal details of around 300,00 customers in the UK and Ireland.

The data exposure occurred due to a non-password protected database – personal details, including names, email addresses, and mobile numbers were left unsecure.

22,745 records and documents containing personal information, including user IDs, were in the exposed dataset from iCabbi, taxi software firm based in Ireland.

According to Jeremiah Fowler, who first discovered and reported the database, the exposed email addresses were from a range of providers and private domains, including: 117,231 Gmail, 65,060 Hotmail, 17,588 Yahoo, 18,099 iCloud, 12,798 Outlook, 7,484 Live, as well as others.

Intriguingly, Fowler also discovered email addresses from major media outlines like the BBC, as well as government agencies such as the NIH, HM Treasury, and Ministry of Justice. University email addresses were also included in the findings.

The database seemed to be a content management storage repository, according to Fowler, used for terms and conditions documents as well as customer data spreadsheets.

Within the folder, however, were other documents that were secured and could not be accessed publicly.


Recommended reading


“The potential risk of cyber criminals knowing the file paths of where documents are stored could allow a targeted brute force attack against the wider network or identifying individual misconfigured documents. I am not saying iCabbi’s network was at imminent risk, but I am providing a hypothetical risk of exposing the file path where customer documents are collected and stored,” Fowler wrote for vpnMentor.

iCabbi has since responded to the disclosure notice, saying: “Thanks again for bringing this to my attention – we have deleted the records. Human error to blame here unfortunately… part of a migration of customers but we should not be using public folders. We are going to engage with customers to make them aware of this breach” as reported by vpnMentor.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data