- Cybernews discovered Carla’s exposed AWS bucket containing 48,000 PDFs containing customer rental data.
- The files included names, email addresses, phone numbers, rental details and travel patterns useful for phishing.
- Carla secured the database after the disclosure; no evidence of malicious access, but risk remains
Car rental comparison and booking platform Carla maintained a database of sensitive customer information unlocked on the open internet, freely available to anyone who knew where to look.
Cybersecurity researchers from Cybernewsreported finding an exposed Amazon Web Services (AWS) bucket containing approximately 48,000 PDF files. These files, which were later determined to belong to Carla, contained car rental details and personal information about the drivers.
Among other things, these files contained supporting documents and confirmation numbers, driver names, email addresses and telephone numbers, rental periods, costs, pick-up and drop-off locations, and general vehicle information.
Carla reacts
Cybernews claims the data could have been used in convincing phishing attacks. Not only would bad actors obtain contact information, but they could also infer individuals’ travel habits, which could be used to build trust with victims – a crucial step in social engineering attacks.
After disclosing the results to Carla, the company locked the database. Currently, there is no evidence that malicious actors have accessed it in the past, but Cybernews says that “if our team has discovered it, it is also possible that malicious actors have automated tools specifically looking for unprotected corporate data.”
The service doesn’t have its own feel. Instead, it functions as a travel booking site, aggregating deals from hundreds of rental providers and allowing users to compare prices and book cars online.
Misconfigured databases remain one of the leading causes of major data leaks. Companies often misunderstand the shared responsibility model of cloud providers, leaving systems with default settings or setting weak, easy-to-guess credentials.
Cybernews also recently reported discovering an exposed ElasticSearch cluster belonging to Nextcloud containing 367,000 records of employee data, customer company data, contracts, and various scripts.
The best antivirus for every budget
Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.




