时间:2025-01-18 15:53:43 来源:网络整理编辑:知識
Login data for more than half a million records tied to vehicle tracking device company SVR Tracking
Login data for more than half a million records tied to vehicle tracking device company SVR Tracking have leaked online, potentially exposing the personal and vehicle data of drivers and businesses using its service.
The leaked repository was first spotted by the Kromtech Security Center, which blamed a misconfigured Amazon AWS S3 bucket that was left publicly accessible for an unknown period of time for the breach. Kromtech first noticed the cache on Sept. 18, according to Gizmodo, and the bucket was closed from public access hours after the security company alerted SVR on Sept. 20.
The records included user login info like emails and passwords, along with VINs (vehicle identification numbers) and license plate numbers, data about the GPS devices, and "other data" collected by SVR Tracking about its devices, customers, and auto dealerships that do business with the company.
SEE ALSO:Equifax has been directing victims to a fake phishing site for weeksThe data was kept in a backup folder called "accounts," which contained 540,642 entries. Some of those entries were associated with multiple vehicles. Kromtech said the total number of devices exposed "could be much larger given the fact that many of the resellers or clients had large numbers of devices for tracking."
The SVR leak contained extensive vehicle location records along with account information. The company offers continuous tracking in case cars are stolen or impounded, collecting reams of GPS data.
The service records "heartbeats" (GPS location beacons) from its devices every four hours, and stores location info for everywhere a monitored car has been for as long as 120 days in the past — meaning that someone who gained access to an account's password could both track a vehicle in real time and build a detailed log of every location it has visited. They could outright steal the car, stalk its driver, or rob a home when they know a vehicle's owner is out and about.
The folder also contained 339 logs with photos and data about vehicle status and maintenance records, along with a document that provided details about 427 dealerships that use SVR's services.
SVR didn't respond directly to Kromtech, although the leaked records were blocked from public access shortly after Kromtech provided info about the leak. The company hasn't replied to our request for comment on the matter, either.
The type of constant monitoring offered by SVR is designed to give car owners some peace of mind with the knowledge that they'll always be in control of their vehicle. This type of leak, however, does the opposite, potentially handing the digital keys to cybercriminals who could've used the data for their own means.
TopicsCybersecurity
Olympian celebrates by ordering an intimidating amount of McDonald's2025-01-18 15:50
體育總局: 國腳嚴禁有新紋身 對已有者勸誡其自行清除2025-01-18 15:07
2021亞洲國家隊賽事射手榜TOP5 :武磊9球位列第三2025-01-18 14:45
廣州城VS海港首發:卡爾多納先發 奧斯卡王燊超出戰2025-01-18 14:44
There's a big piece of fake chicken stuck to this phone case2025-01-18 14:41
登貝萊身邊人:巴薩說沒錢續約 但他們卻想簽哈蘭德2025-01-18 14:07
外媒關注體育總局發布國腳紋身禁令 :評論褒貶不一2025-01-18 13:56
記者:青島為保級做了很多實際工作 補發工資+增加贏球獎2025-01-18 13:56
Researchers create temporary tattoos you can use to control your devices2025-01-18 13:21
巴薩談崩登貝萊引連鎖效應 被推薦馬夏爾等英超三廢2025-01-18 13:17
Twitter grants everyone access to quality filter for tweet notifications2025-01-18 15:44
太戲劇 !津門虎補時絕殺搶回保級主動權 下輪贏球就能回家2025-01-18 15:24
張外龍:感謝重慶隊員們一直克服困難 希望最終結果是好的2025-01-18 15:17
西媒:登貝萊免簽尤文已達協議 巴黎欲重金截殺2025-01-18 14:57
This app is giving streaming TV news a second try2025-01-18 14:50
巴薩甩2.8億兩廢將 ?庫鳥或回巴西 熱刺欲購格子2025-01-18 14:47
巴薩甩2.8億兩廢將 ?庫鳥或回巴西 熱刺欲購格子2025-01-18 14:26
詹俊評2021年度最佳陣容:梅西領銜 無C羅姆巴佩2025-01-18 14:00
Researchers create temporary tattoos you can use to control your devices2025-01-18 13:52
中超保級形勢突變 津門虎重慶大連人最後一輪生死戰2025-01-18 13:36