drivesure data breach

Drivesure, a dealership service provider, was hit by a data breach in December of last year. In the aftermath, 26GB of private data was downloaded and distributed via hacking forums. The data breached included names of addresses, addresses, as well as phone numbers of 3.2 millions of buyers and also text messages and emails between customers and traders, vehicle VINs, and service records. In addition, more than 93 000 hashed bcrypt passwords were released. While bcrypt hashes are considered superior to older methods like SHA1 or MD5 However, they could be used to force brute-force after downloading, reports Risk Based Security.

Hacker “pompompurin” described the leaked user data and files in a lengthy blog post on Raidforums. This is unusual since hackers usually only share important segments or trimmed down versions of databases they have found.

The database was exposed as a result of a misconfiguration error in an AWS bucket used by the company according to CISO Magazine. The AWS bucket had been left unprotected, allowing anyone to access the contents and data. This included over a million email addresses in plaintext, and passwords encrypted with the bcrypt encryption method.

Users of Drivesure should be concerned about the breach, since they may become victims of identity theft or fraud if their information is stolen. Anyone who uses the site should immediately change their passwords. They should also consider changing their login credentials on other websites where they use the same credentials.