In brief: An unsecured AWS storage bucket belonging to car rental aggregator Carla exposed hundreds of new booking documents daily, containing complete driver identities, travel dates, and vehicle details to potential attackers.
Security researchers from Cybernews discovered on June 3, 2026 a publicly accessible cloud storage bucket of car rental aggregator Carla containing approximately 48,000 booking confirmations. The data was only secured after notification on June 29, 2026.
Carla, a Turkey-based aggregator for car rental offers with presence at over 20,000 locations in 180 countries and approximately 2 million users annually, had configured a data storage on an Amazon Web Services instance that was accessible without access restrictions. The storage bucket contained around 48,000 PDF files with booking confirmations; hundreds of new documents were added daily, indicating an active data flow in production.
Each booking confirmation included a combination of sensitive driver information (full names, email addresses, phone numbers), booking parameters (reference numbers, rental periods, total costs, pickup and return locations) as well as vehicle characteristics (model, class, transmission type). This volume of data enables attackers to reconstruct travel patterns of individual persons and predict their absence from their home location with precise timing.
The Cybernews research team identified two attack scenarios: First, criminals could use fake notifications about alleged reservation problems to extract additional personal information through social engineering. Second, the rental periods allow inferences about absence times from home addresses, paving the way for burglary crimes. At the time of discovery, the researchers had no indications of data misuse that had already occurred.
Source: www.it-daily.net · Published July 23, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.