Skip to main content
Back
Fasten

Fasten Data Breach (2017)

Fasten

highVERIS
Disclosed

November 1, 2017

3068 days ago

Records

1.0M

Confirmed

Root Cause

Misconfiguration

Industry

Transportation

Description

Boston-based ride-hailing hopeful Fasten has coughed to a million-customer data breach that happened because someone left a database lying around unsecured. The breach was turned up by cloud-crowd Kromtech, whose Bob Diachenko wrote late last week that the company had a misconfigured Apache Hive database exposed on the Internet. Hive is a data warehouse system built on top of Hadoop. “The server was left open for end-user access and this also let anyone with an internet connection access Fasten’s internal data”, he wrote. The exposed customer data included names, e-mails, telephone numbers, IMEI codes, trip details (pick-up and drop-off points), and links to photos. Corporate data, including a few thousand driver profiles, routes, comments about drivers, car registration, and photos of drivers’ vehicles.

Fasten Data Breach (2017) - 1.0M Records | ExposedMap