, , , ,

Hotai Motor exposed thousands of iRent customer documents

Taiwanese automotive conglomerate Hotai Motor exposed reams of personal customer data from its car rental and carshare unit, iRent, until a security researcher found the data online last week.

Even then, it took the company a week — and the intervention of the Taiwanese government — to act.

Hotai Motor is one of the largest financial holdings companies in Taiwan, and also the Taiwanese distributor for Toyota. iRent is a popular auto service app, bought by Hotai in 2022, which allows customers to pay hourly to rent cars that can be found either free-floating or at a depot.

iRent reportedly has over 1.1 million registered cars and 580,000 iRent users.

Security researcher Anurag Sen discovered a database containing iRent customers’ full names, cell phone numbers and email addresses, home addresses, photos of their drivers’ licenses, and partially redacted payment card details, on a Hotai-owned cloud server that was inadvertently accessible from the internet.

Because the database was not password-protected, anyone on the internet could access the iRent customer data just by knowing its IP address.

Sen said the exposed database also contained millions of partial credit card numbers, and at least 100,000 customer identification documents, as well as selfies, signatures, and rental vehicle details.

TechCrunch reviewed a portion of the exposed data and confirmed Sen’s findings. Internet records by Shodan, a search engine for exposed devices and databases, show the database was spilling data as far back as May 2022 and contained about 4.2 terabytes of data at the time it was secured.

TechCrunch sent several emails this week to Hotai Motor with details of the exposed database, but we did not receive a reply. All the while, the database was updating with new customer data in real time.

On January 28, TechCrunch subsequently contacted Taiwan’s Ministry of Digital Affairs, the government department that regulates and oversees the country’s internet and telecoms, for help in disclosing the security lapse to the company. In an emailed response, Taiwan’s minister for digital affairs Audrey Tang told TechCrunch that the exposed database had been flagged with Taiwan’s national computer emergency response team, known as TWCERT/CC. Within an hour, the exposed iRent database became inaccessible.

A short time later, Hotai Motor confirmed it had secured the database. “We had blocked the outside connection to this IP immediately.” Hotai said that it would inform customers whose data was exposed.

It’s not clear if anyone else, other than Sen, found the database during the nine months it was spilling data.

It’s not the first time a car rental company has compromised its own customers’ data. Back in 2017, Hertz accidentally leaked the personal data of 36,000 customers. France’s national data protection authority fined Hertz France €40,000 at the time because the data was found to be easily accessible online.

Hotai Motor exposed thousands of iRent customer documents by Zack Whittaker originally published on TechCrunch

https://techcrunch.com/2023/01/30/hotai-motor-exposed-irent-customer-data/


January 2025
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  

About Us

Welcome to encircle News! We are a cutting-edge technology news company that is dedicated to bringing you the latest and greatest in everything tech. From automobiles to drones, software to hardware, we’ve got you covered.

At encircle News, we believe that technology is more than just a tool, it’s a way of life. And we’re here to help you stay on top of all the latest trends and developments in this ever-evolving field. We know that technology is constantly changing, and that can be overwhelming, but we’re here to make it easy for you to keep up.

We’re a team of tech enthusiasts who are passionate about everything tech and love to share our knowledge with others. We believe that technology should be accessible to everyone, and we’re here to make sure it is. Our mission is to provide you with fun, engaging, and informative content that helps you to understand and embrace the latest technologies.

From the newest cars on the road to the latest drones taking to the skies, we’ve got you covered. We also dive deep into the world of software and hardware, bringing you the latest updates on everything from operating systems to processors.

So whether you’re a tech enthusiast, a business professional, or just someone who wants to stay up-to-date on the latest advancements in technology, encircle News is the place for you. Join us on this exciting journey and be a part of shaping the future.

Podcasts

TWiT 1014: Just Say It's Capitalism – CES 2025, Meta News, Newag DRM This Week in Tech (Audio)

The panel discusses CES 2025 How Watch Duty's wildfire tracking app became a crucial lifeline for LA Worst in Show awards 2025 Aaron Swartz v Sam Altman We've not been trained for this: life after the Newag DRM disclosure All the Meta stuff (fact checking, etc.) Heritage Foundation plans to 'identify and target' Wikipedia editors The Government Wants to Protect Robux From Hackers Twitch Streamers Come Home After Big-Money Contracts at Rivals Dried Up Candy Crush, Tinder, MyFitnessPal: See the Thousands of Apps Hijacked to Spy on Your Location Host: Leo Laporte Guests: Nicholas De Leon, Fr. Robert Ballecer, SJ, and Cory Doctorow Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: coda.io/twit expressvpn.com/twit threatlocker.com for This Week in Tech uscloud.com bitwarden.com/twit
  1. TWiT 1014: Just Say It's Capitalism – CES 2025, Meta News, Newag DRM
  2. TWiT 1013: Calamari in Crisis – Touching the Sun, Fake Spotify Artists, Banished Words
  3. TWiT 1012: Our Best Of 2024 – The Best Moments From TWiT's 2024
  4. TWiT 1011: The Year in Review – A Look at the Top Stories of 2024
  5. TWiT 1010: The Densest State in the US – TikTok Ban, Drones Over Jersey, GM Quits Robotaxis