• 2 min read
Carla exposed 48,000 rental PDFs online
Cybernews found an open AWS bucket tied to Carla with 48,000 PDFs containing customer names, emails, phone numbers, and rental details.

Image: TechRadar
Carla, a car rental comparison and booking platform, left a database containing sensitive customer information exposed on the open internet, according to Cybernews. Researchers said they found an unsecured Amazon Web Services (AWS) bucket holding roughly 48,000 PDF files linked to the company.
The files reportedly contained rental vouchers and confirmation numbers, along with customers' names, email addresses, phone numbers, rental periods, costs, pick-up and drop-off locations, and general vehicle information. Cybernews said that combination of personal and trip data could support highly convincing phishing attacks, since it may also reveal users' travel patterns and help attackers build trust in social engineering scams.
After Cybernews disclosed the issue, Carla secured the database. There is currently no evidence that malicious actors accessed the data, but the researchers warned that exposed corporate systems are often discovered by automated tools used by threat actors.
Carla does not operate its own vehicle fleet. Instead, it aggregates offers from hundreds of rental providers, allowing users to compare prices and book cars online.

Recommended reading
Flock Drops Distress Detection After Privacy Backlash
The incident is another example of how misconfigured cloud databases continue to drive data exposure. As TechRadar notes, companies still frequently misread the cloud shared responsibility model, leave default settings in place, or rely on weak credentials.
Cybernews recently reported a separate exposure involving an ElasticSearch cluster tied to Nextcloud, with 367,000 records including employee data, client company data, contracts, and scripts.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via TechRadar


