• Terms and Conditions
  • Privacy Policy
  • DMCA
  • Disclaimer
  • Cookie Privacy Policy
  • Contact Us
News Zents
No Result
View All Result
  • Home
  • Business
  • Economy
  • Fintech
  • Finance
  • Insurance
  • Market
  • Startups
No Result
View All Result
  • Home
  • Business
  • Economy
  • Fintech
  • Finance
  • Insurance
  • Market
  • Startups
News Zents
No Result
View All Result
Home Startups

Hotai Motor exposed thousands of iRent customer documents • TechCrunch

Zack Whittaker by Zack Whittaker
January 31, 2023
0


Taiwanese automotive conglomerate Hotai Motor exposed reams of personal customer data from its car rental and carshare unit, iRent, until a security researcher found the data online last week.

Even then, it took the company a week — and the intervention of the Taiwanese government — to act.

Hotai Motor is one of the largest financial holdings companies in Taiwan, and also the Taiwanese distributor for Toyota. iRent is a popular auto service app, bought by Hotai in 2022, which allows customers to pay hourly to rent cars that can be found either free-floating or at a depot.

iRent reportedly has over 1.1 million registered cars and 580,000 iRent users.

Security researcher Anurag Sen discovered a database containing iRent customers’ full names, cell phone numbers and email addresses, home addresses, photos of their drivers’ licenses, and partially redacted payment card details, on a Hotai-owned cloud server that was inadvertently accessible from the internet.

Because the database was not password-protected, anyone on the internet could access the iRent customer data just by knowing its IP address.

Sen said the exposed database also contained millions of partial credit card numbers, and at least 100,000 customer identification documents, as well as selfies, signatures, and rental vehicle details.

TechCrunch reviewed a portion of the exposed data and confirmed Sen’s findings. Internet records by Shodan, a search engine for exposed devices and databases, show the database was spilling data as far back as May 2022, and contained about 4.2 terabytes of data at the time it was secured.

TechCrunch sent several emails this week to Hotai Motor with details of the exposed database but we did not receive a reply. All the while, the database was updating with new customer data in real-time.

TechCrunch subsequently contacted Taiwan’s Ministry of Digital Affairs, the government department that regulates and oversees the country’s internet and telecoms, on January 28 for help in disclosing the security lapse to the company. In an emailed response, Taiwan’s minister for digital affairs Audrey Tang told TechCrunch that the exposed database had been flagged with Taiwan’s national computer emergency response team, known as TWCERT/CC. Within an hour, the exposed iRent database became inaccessible.

A short time later, Hotai Motor confirmed it had secured the database. “We had blocked the outside connection to this IP immediately.” Hotai said that it would inform customers whose data was exposed.

It’s not clear if anyone else, other than Sen, found the database during the nine months it was spilling data.

It’s not the first time a car rental company has compromised its own customers’ data. Back in 2017, Hertz accidentally leaked the personal data of 36,000 customers. France’s national data protection authority fined Hertz France €40,000 at the time because the data was found to be easily accessible online.

Tags: customerDocumentsexposedHotaiiRentMotorTechCrunchThousands
Advertisement Banner
Zack Whittaker

Zack Whittaker

Next Post

Wisr delivers maiden profitable quarter

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Will Adding an Accessory Dwelling Unit Pay Off?

November 17, 2022

Adani Power Amalgamates Six Subsidiary Companies

March 7, 2023

India vs South Africa, T20 World Cup: Markram, Miller steer Proteas over the line after Ngidi, Parnell ‘out-bounce’ Team India

October 30, 2022

Netcetera’s Digital Wallet and Checkout Experience Solutions Wins Juniper Awards

October 13, 2022

Should You Invest in Turnkey Properties or Fixer-Uppers?

October 7, 2022

zomato share price: Risk-reward not compelling enough, ICICI Securities maintains ‘hold’ on Zomato

October 17, 2022

Recent News

Fed sees credit drawdown looming, shifts towards pause on rate hikes By Reuters

March 23, 2023

Founder Mental Health Pledge signed by 50+ VC Firms in a few days since launching, covering 14K+ startup founders to use therapy as a business expense

March 22, 2023

Categories

  • Business
  • Economy
  • Finance
  • Fintech
  • Insurance
  • Market
  • Regulation
  • Startups
  • Uncategorized

This is an online news portal designed to provide the latest market news, world news, fintech, and more like that from around the world. We are committed to sharing only high-quality content from the world's best trusted sources.

  • Terms and Conditions
  • Privacy Policy
  • DMCA
  • Disclaimer
  • Cookie Privacy Policy
  • Contact Us

© 2015 - 2022 Newszents - All contents Copyright Newszents. All rights reserved

No Result
View All Result
  • Home
  • Business
  • Economy
  • Finance
  • Fintech
  • Insurance
  • Market
  • Startups

© 2015 - 2022 Newszents - All contents Copyright Newszents. All rights reserved