The internet breach of login credentials for 540K records that belonged to SVR Tracking, a firm that makes vehicle tracking devices, has occurred.
The event may have exposed the private information and car specifics of drivers and companies that make use of the SVR Tracking service.
The professionals from Kromtech Security Centre found the unlocked AWS S3 cloud storage bucket that had SVR Tracking data.
Using a physical tracking device that is concealed within the vehicles, the SVR Tracking service enables its customers to track their vehicles in real time.
Source: https://securityaffairs.com/63343/data-breach/svr-tracking-data-leak.html
TPRM report: https://scoringcyber.rankiteo.com/company/svr-tracking
"id": "svr132111223",
"linkid": "svr-tracking",
"type": "Breach",
"date": "09/2017",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Drivers and companies using SVR '
'Tracking service',
'industry': 'Vehicle Tracking',
'name': 'SVR Tracking',
'size': 'Small',
'type': 'Company'}],
'attack_vector': 'Unsecured Cloud Storage',
'data_breach': {'number_of_records_exposed': '540,000',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Login credentials',
'Private information',
'Car specifics']},
'description': 'An internet breach of login credentials for 540K records that '
'belonged to SVR Tracking, a firm that makes vehicle tracking '
'devices, has occurred. The event may have exposed the private '
'information and car specifics of drivers and companies that '
'make use of the SVR Tracking service. The professionals from '
'Kromtech Security Centre found the unlocked AWS S3 cloud '
'storage bucket that had SVR Tracking data. Using a physical '
'tracking device that is concealed within the vehicles, the '
'SVR Tracking service enables its customers to track their '
'vehicles in real time.',
'impact': {'data_compromised': ['Private information of drivers',
'Car specifics of companies'],
'systems_affected': ['AWS S3 cloud storage bucket']},
'motivation': 'Unknown',
'response': {'third_party_assistance': ['Kromtech Security Centre']},
'threat_actor': 'Unknown',
'title': 'Internet Breach of Login Credentials at SVR Tracking',
'type': 'Data Breach',
'vulnerability_exploited': 'Unlocked AWS S3 bucket'}