时间:2025-03-01 00:57:17 来源:网络整理编辑:知識
Login data for more than half a million records tied to vehicle tracking device company SVR Tracking
Login data for more than half a million records tied to vehicle tracking device company SVR Tracking have leaked online, potentially exposing the personal and vehicle data of drivers and businesses using its service.
The leaked repository was first spotted by the Kromtech Security Center, which blamed a misconfigured Amazon AWS S3 bucket that was left publicly accessible for an unknown period of time for the breach. Kromtech first noticed the cache on Sept. 18, according to Gizmodo, and the bucket was closed from public access hours after the security company alerted SVR on Sept. 20.
The records included user login info like emails and passwords, along with VINs (vehicle identification numbers) and license plate numbers, data about the GPS devices, and "other data" collected by SVR Tracking about its devices, customers, and auto dealerships that do business with the company.
SEE ALSO:Equifax has been directing victims to a fake phishing site for weeksThe data was kept in a backup folder called "accounts," which contained 540,642 entries. Some of those entries were associated with multiple vehicles. Kromtech said the total number of devices exposed "could be much larger given the fact that many of the resellers or clients had large numbers of devices for tracking."
The SVR leak contained extensive vehicle location records along with account information. The company offers continuous tracking in case cars are stolen or impounded, collecting reams of GPS data.
The service records "heartbeats" (GPS location beacons) from its devices every four hours, and stores location info for everywhere a monitored car has been for as long as 120 days in the past — meaning that someone who gained access to an account's password could both track a vehicle in real time and build a detailed log of every location it has visited. They could outright steal the car, stalk its driver, or rob a home when they know a vehicle's owner is out and about.
The folder also contained 339 logs with photos and data about vehicle status and maintenance records, along with a document that provided details about 427 dealerships that use SVR's services.
SVR didn't respond directly to Kromtech, although the leaked records were blocked from public access shortly after Kromtech provided info about the leak. The company hasn't replied to our request for comment on the matter, either.
The type of constant monitoring offered by SVR is designed to give car owners some peace of mind with the knowledge that they'll always be in control of their vehicle. This type of leak, however, does the opposite, potentially handing the digital keys to cybercriminals who could've used the data for their own means.
TopicsCybersecurity
Tributes flow after death of former Singapore president S.R. Nathan2025-03-01 00:51
中超第二階段裁判名單敲定 馬寧等國際裁判員參與執法2025-03-01 00:50
西媒:巴薩要改變的太多了 這麽踢連歐聯也贏不了2025-03-01 00:24
尤文VS馬爾默首發:迪巴拉小基恩先發 阿圖爾出戰2025-03-01 00:06
Old lady swatting at a cat ends up in Photoshop battle2025-02-28 23:53
曝廣州預備隊教練組將馳援一線隊 劉智宇將輔助鄭智2025-02-28 23:30
歐冠小組賽印象:英超強勢拜仁製霸 巴薩西甲沒落2025-02-28 23:27
廣州隊更新一線隊名單 :阿蘭艾克森缺席 蔣光太洛國富在列2025-02-28 22:43
Tesla's rumored P100D could make Ludicrous mode even more Ludicrous2025-02-28 22:24
貝利再次住院接受結腸腫瘤治療 預計幾日後可出院2025-02-28 22:15
This weird squid looks like it has googly eyes, guys2025-03-01 00:48
涼了 ?巴薩簽曼城妖童或違反財政公平 恐無法注冊2025-03-01 00:42
武漢三鎮官宣代理主帥佩德羅轉正 率隊14連勝衝超在即2025-03-01 00:32
巴薩18年來首次無緣歐冠淘汰賽 神奇紀錄始於梅西終於梅西2025-03-01 00:17
Mom discovers security cameras hacked, kids' bedroom livestreamed2025-02-28 23:57
西媒:巴薩要改變的太多了 這麽踢連歐聯也贏不了2025-02-28 23:55
曼城考慮滕哈特未來接班瓜帥 將麵臨紅魔巴黎競爭2025-02-28 23:51
皇馬瘋狂九連勝!16次獲得歐冠小組第一 僅次巴薩2025-02-28 22:32
Darth Vader is back. Why do we still care?2025-02-28 22:31
津媒:津門虎隊進入"戰時狀態" 8場保級戰就在眼前2025-02-28 22:15