Rental giant Carla leaks usernames, email addresses and phone numbers ahead of summer vacation


  • Cybernews discovered Carla’s exposed AWS bucket containing 48,000 PDFs containing customer rental data.
  • The files included names, email addresses, phone numbers, rental details and travel patterns useful for phishing.
  • Carla secured the database after the disclosure; no evidence of malicious access, but risk remains

Car rental comparison and booking platform Carla maintained a database of sensitive customer information unlocked on the open internet, freely available to anyone who knew where to look.

Cybersecurity researchers from Cybernewsreported finding an exposed Amazon Web Services (AWS) bucket containing approximately 48,000 PDF files. These files, which were later determined to belong to Carla, contained car rental details and personal information about the drivers.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top