Rental giant Carla leaks usernames, emails and phone numbers ahead of summer holidays



  • Cybernews found Carla’s exposed AWS repository with 48,000 PDF files containing customer rental data
  • The files included names, emails, phone numbers, rental details and travel patterns useful for phishing.
  • Carla secured the database after disclosure; There is no evidence of malicious access, but the risk remains.

Carla, the rental car comparison and booking platform, kept a database of confidential customer information unlocked on the internet, freely available to anyone who knew where to look.

Cybersecurity researchers cyber newsreported finding an exposed Amazon Web Services (AWS) repository with approximately 48,000 PDF files. These files, later determined to belong to Carla, contained car rental details and drivers’ personal information.

Leave a Comment

Your email address will not be published. Required fields are marked *