Login data for more than half a million records tied to vehicle tracking device company SVR Tracking have leaked online, potentially exposing the personal and vehicle data of drivers and businesses using its service.
The leaked repository was first spotted by the Kromtech Security Center, which blamed a misconfigured Amazon AWS S3 bucket that was left publicly accessible for an unknown period of time for the breach. Kromtech first noticed the cache on Sept. 18, according to Gizmodo, and the bucket was closed from public access hours after the security company alerted SVR on Sept. 20.
The records included user login info like emails and passwords, along with VINs (vehicle identification numbers) and license plate numbers, data about the GPS devices, and "other data" collected by SVR Tracking about its devices, customers, and auto dealerships that do business with the company.
SEE ALSO:Equifax has been directing victims to a fake phishing site for weeksThe data was kept in a backup folder called "accounts," which contained 540,642 entries. Some of those entries were associated with multiple vehicles. Kromtech said the total number of devices exposed "could be much larger given the fact that many of the resellers or clients had large numbers of devices for tracking."
The SVR leak contained extensive vehicle location records along with account information. The company offers continuous tracking in case cars are stolen or impounded, collecting reams of GPS data.
The service records "heartbeats" (GPS location beacons) from its devices every four hours, and stores location info for everywhere a monitored car has been for as long as 120 days in the past — meaning that someone who gained access to an account's password could both track a vehicle in real time and build a detailed log of every location it has visited. They could outright steal the car, stalk its driver, or rob a home when they know a vehicle's owner is out and about.
The folder also contained 339 logs with photos and data about vehicle status and maintenance records, along with a document that provided details about 427 dealerships that use SVR's services.
SVR didn't respond directly to Kromtech, although the leaked records were blocked from public access shortly after Kromtech provided info about the leak. The company hasn't replied to our request for comment on the matter, either.
The type of constant monitoring offered by SVR is designed to give car owners some peace of mind with the knowledge that they'll always be in control of their vehicle. This type of leak, however, does the opposite, potentially handing the digital keys to cybercriminals who could've used the data for their own means.
TopicsCybersecurity
(责任编辑:知識)
You will love/hate Cards Against Humanity's new fortune cookies
This site is a pirate radio for the most popular streaming services
Why most self
'The Office' children's book is here to inspire a whole new generation of fans
Here's what 'Game of Thrones' actors get up to between takesIs Samsung's Galaxy Note7 really the best phone?
On this week's。 MashTalk。, Lance, Pete and I talk about the new hot smartphone in town: Samsung's Ga
...[详细]I used emoji to order groceries
Generally, reverting back to pictographs to communicate embarrasses me.I've resisted emoji in most o
...[详细]Here's the real reason Mark Zuckerberg is so afraid of TikTok
Mark Zuckerberg has already made it clear he has no love for TikToK, but we now have an even clearer
...[详细]Twitter is bringing Tapbacks to direct messages
I regret to inform you that Tapbacks have come to Twitter DMs. That's right: The worst part of texti
...[详细]Tourist survives for month in frozen New Zealand wilderness after partner dies
A tourist from the Czech Republic, whose partner fell to his death, survived a harrowing month in th
...[详细]The coronavirus has sent a video game about wiping out humanity to #1
Video game Plague Inc. has had a surge of popularity in light of the ongoing coronavirus outbreak, w
...[详细]Billie Eilish looking confused AF at the Oscars is a real meme mood
Billie Eilish may be a singer, but if she ever decides to go into acting she already has the "confus
...[详细]Intel, Vivo and NTT withdraw from Mobile World Congress
UPDATE: Feb. 11, 2020, 3:32 p.m. CET A report from Spanish outlet La Vanguardia says the GSMA will h
...[详细]Old lady swatting at a cat ends up in Photoshop battle
We all have that relative who gets annoyed with the cat.。This timeless photo of an old woman shooing
...[详细]The Human Screenome Project wants to 'sequence' our smartphone use
Is constant smartphone surveillance still terrifying if it's for science?Three Stanford University p
...[详细]Tourist survives for month in frozen New Zealand wilderness after partner dies

New renders show what Apple's new budget phone could look like, whatever it's called
