Security News > 2024 > April > Global taxi software vendor exposes details of nearly 300K across UK and Ireland

Global taxi software vendor exposes details of nearly 300K across UK and Ireland
2024-04-11 09:30

Exclusive Taxi software biz iCabbi recently fixed an issue that exposed the personal information of nearly 300,000 individuals via an unprotected database.

According to research shared with The Register ahead of publication, the details of individuals with senior roles in media outlets such as the BBC and various government departments such as His Majesty's Treasury, the UK Home Office, and the Ministry of Justice were included.

Such data could theoretically be used in convincing phishing scams that impersonate the taxi company, using the victim's full name and appearing legitimate by knowing other details, including their user IDs.

Dublin-based iCabbi provides software to more than 800 taxi fleets in 15 countries, including apps that comprise an entire platform.

The exposed data appears to be related to the customer-facing apps powered by iCabbi's technology, given that staff details weren't included in the exposure.

Asked how Fowler was able to link the data to iCabbi, he said: "[iCabbi was] the common denominator.


News URL

https://go.theregister.com/feed/www.theregister.com/2024/04/11/icabbi_database_exposure/