- Cybernews found Carla’s exposed AWS repository with 48,000 PDF files containing customer rental data
- The files included names, emails, phone numbers, rental details and travel patterns useful for phishing.
- Carla secured the database after disclosure; There is no evidence of malicious access, but the risk remains.
Carla, the rental car comparison and booking platform, kept a database of confidential customer information unlocked on the internet, freely available to anyone who knew where to look.
Cybersecurity researchers cyber newsreported finding an exposed Amazon Web Services (AWS) repository with approximately 48,000 PDF files. These files, later determined to belong to Carla, contained car rental details and drivers’ personal information.
Among other things, these files contained vouchers and confirmation numbers, driver names, email addresses and phone numbers, rental periods, costs, pick-up and drop-off locations, as well as general vehicle information.
carla reacts
Cybernews says the data could have been used to convince phishing attacks. Malicious actors would not only obtain contact information, but could also deduce people’s travel patterns, which could be used to establish trust with victims, a crucial step in social engineering attacks.
After revealing the findings to Carla, the company locked the database. Currently, there is no evidence that malicious actors have accessed it in the past, but Cybernews says that “if our team discovered it, it may also have been done by threat actors who have automated tools that specifically look for unprotected corporate data.”
The service has no feel of its own. Instead, it functions as a travel booking site, aggregating offers from hundreds of rental providers and offering users to compare prices and reserve cars online.
Misconfigured databases remain one of the key causes of large data breaches. Enterprises often misunderstand cloud providers’ shared responsibility model, leaving systems with default configurations or setting up weak, easy-to-guess credentials.
cyber news It also recently reported discovering an exposed ElasticSearch cluster belonging to Nextcloud that contains 367,000 records of employee data, client company data, contracts, and various scripts.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.




