Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

Car Dealer Marketing Firm Exposed 198 Million Data Records

A publicly accessible, unprotected database belonging to car dealership marketing firm Dealer Leads was found to expose 198 million records, including personally identifiable information, Security Discovery reports.

A publicly accessible, unprotected database belonging to car dealership marketing firm Dealer Leads was found to expose 198 million records, including personally identifiable information, Security Discovery reports.

The database contained 413GB of data representing a compilation of information on potential car buyers, vehicles, loan and finance inquiries, log data with IP addresses of visitors, and more.

With thousands of automotive sites, each specifically aimed at a precise buyer demographic or behavioral characteristic, Dealer Leads delivers content relevant and related to the auto industry or specific target keywords.

Founded in 2015 and based in Calabasas, California, Dealer Leads says it provides “high volume, high quality website traffic for franchise and independent car dealerships.”

The exposed database was set to be “open and visible in any browser,” meaning that anyone connected to the Internet could access the data without having to provide administrative credentials.

Security Discovery also revealed that the database contained records with name, email, phone, address, IP, and other sensitive or identifiable information, in plain text.

Information such as IP addresses, ports, pathways, and storage info, the security firm notes, could be exploited by cybercriminals to access deeper into an organization’s network.

The company restricted public access to the database immediately after being notified on the matter, but the data was exposed for an undetermined period of time, when anyone could have accessed the millions of records there.

Advertisement. Scroll to continue reading.

“It is unclear if Dealer Leads has notified individuals, dealerships, or authorities about the data incident. Because of the size and scope of the network applicants and potential customers may not know if their data was exposed,” Security Discovery notes.

Related: Unprotected Database Exposes Details of Honda’s Internal Network

Related: Unprotected Database Stored Information on 80 Million U.S. Households

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Artificial Intelligence

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Incident Response

Microsoft has rolled out a preview version of Security Copilot, a ChatGPT-powered tool to help organizations automate cybersecurity tasks.