时间:2025-04-03 10:02:30 来源:网络整理编辑:知識
Login data for more than half a million records tied to vehicle tracking device company SVR Tracking
Login data for more than half a million records tied to vehicle tracking device company SVR Tracking have leaked online, potentially exposing the personal and vehicle data of drivers and businesses using its service.
The leaked repository was first spotted by the Kromtech Security Center, which blamed a misconfigured Amazon AWS S3 bucket that was left publicly accessible for an unknown period of time for the breach. Kromtech first noticed the cache on Sept. 18, according to Gizmodo, and the bucket was closed from public access hours after the security company alerted SVR on Sept. 20.
The records included user login info like emails and passwords, along with VINs (vehicle identification numbers) and license plate numbers, data about the GPS devices, and "other data" collected by SVR Tracking about its devices, customers, and auto dealerships that do business with the company.
SEE ALSO:Equifax has been directing victims to a fake phishing site for weeksThe data was kept in a backup folder called "accounts," which contained 540,642 entries. Some of those entries were associated with multiple vehicles. Kromtech said the total number of devices exposed "could be much larger given the fact that many of the resellers or clients had large numbers of devices for tracking."
The SVR leak contained extensive vehicle location records along with account information. The company offers continuous tracking in case cars are stolen or impounded, collecting reams of GPS data.
The service records "heartbeats" (GPS location beacons) from its devices every four hours, and stores location info for everywhere a monitored car has been for as long as 120 days in the past — meaning that someone who gained access to an account's password could both track a vehicle in real time and build a detailed log of every location it has visited. They could outright steal the car, stalk its driver, or rob a home when they know a vehicle's owner is out and about.
The folder also contained 339 logs with photos and data about vehicle status and maintenance records, along with a document that provided details about 427 dealerships that use SVR's services.
SVR didn't respond directly to Kromtech, although the leaked records were blocked from public access shortly after Kromtech provided info about the leak. The company hasn't replied to our request for comment on the matter, either.
The type of constant monitoring offered by SVR is designed to give car owners some peace of mind with the knowledge that they'll always be in control of their vehicle. This type of leak, however, does the opposite, potentially handing the digital keys to cybercriminals who could've used the data for their own means.
TopicsCybersecurity
Did our grandparents have the best beauty advice?2025-04-03 10:02
官方:2022U23亞洲杯於2022年9月6日在烏茲別克斯坦舉行2025-04-03 09:54
米蘭VS曼聯前瞻:伊布複出戰舊主 桃園德比決一死戰2025-04-03 09:14
巴薩續約梅西報價曝光:降薪三成 換一份終身合同2025-04-03 09:07
Darth Vader is back. Why do we still care?2025-04-03 08:50
廣州城簽約內援嚐試"一年合同" 左後衛補強正聯係江蘇大將2025-04-03 08:20
朱廣滬:足球就是我的生命 隻要不離開足球我願不斷付出2025-04-03 08:19
相比艾克森們為何大家更喜歡穀愛淩? 文化認同+賽場表現佳2025-04-03 08:02
Researchers create temporary tattoos you can use to control your devices2025-04-03 07:38
尷尬 !江蘇FC退賽造奇觀 中超足協杯冠軍均無緣亞冠2025-04-03 07:35
This 'sh*tpost' bot makes terrible memes so you don't have to2025-04-03 09:52
拜仁VS拉齊奧首發:萊萬PK因莫比萊 阿方索替補2025-04-03 09:03
廣州城簽約內援嚐試"一年合同" 左後衛補強正聯係江蘇大將2025-04-03 08:46
泰山隊將熱身海港+國足 全力以赴出戰李鐵將迎考驗2025-04-03 08:35
Two states took big steps this week to get rid of the tampon tax2025-04-03 08:28
津門虎外援蘇亞雷斯收到FIFA裁定 完成解約恢複自由身2025-04-03 08:19
熱刺前瞻:孫興慜缺陣貝爾凱恩扛大旗 穆帥衝神跡2025-04-03 08:19
塞爾維亞前總統之子參加U16國足主帥麵試 職業履曆豐富2025-04-03 08:02
The five guys who climbed Australia's highest mountain, in swimwear2025-04-03 07:50
官方:2022U23亞洲杯於2022年9月6日在烏茲別克斯坦舉行2025-04-03 07:30