Over half a million transportation industry credit reports were left unsecured online


An unsecured database containing 822k records including 600k credit reports related to the US and Canadian transportation industry has been discovered online.
Security researcher Jeremiah Fowler together with the Website Planet research team found the database which contained detailed information on trucking, transport companies and even individual drivers.
The data itself appears to be connected to credit accounts, loans, repayment and debt collections and includes banking information and Tax ID numbers. However, many of the Tax IDs were consistent with what seems to be Social Security Numbers (SSNs) and were stored in plain text.
At risk
Upon further investigation, Fowler and the Website Planet research team found multiple references as well as internal emails and usernames to the Florida-based company TransCredit. Just as Experian, TransUnion and Equifax provide credit scores to consumers, TransCredit created a “credit score” for the transportation industry that rates shippers and brokers and assigns a risk assessment score from 0 to 99.
The records stored in the unsecured database could give an attacker an overview of a carrier or independent operator’s entire business as they include information regarding late payments, non-payment, bankruptcy, collections and more.
Potential for fraud and scams
Although Fowler and the Website Planet research team sent a responsible disclosure notice to TransCredit immediately following their discovery and public access to the database was restricted shortly after, cybercriminals and other hackers could have downloaded its contents while it wasn’t password protected.
While the pandemic has already led to a driver and labor shortage, transportation companies could also now be at risk of fraud and other scams. This is because the database contained enough information for an attacker to craft believable phishing campaigns as well as tax and repair invoice scams. The inclusion of Tax ID data could also be used by a cybercriminal to build trust with potential victims using social engineering.
Although there were numerous references to TransCredit inside the now secured database, Fowler and the Website Planet research team did not receive a reply from anyone at the company verifying the data did indeed belong to it. This means that the data could have been exposed by a contractor or by another third party that had access to the reports in question.
The only thing companies and independent contractors whose information was exposed can do to protect themselves from fraud and scams is to validate each and every payment or information request. Thankfully though as the database was secured quickly, it’s possible that its contents weren’t downloaded by anyone else for nefarious purposes.
Fowler provided further insight on how the data contained in this exposed database could be used as a working list for bad actors in an email to TechRadar Pro, saying:
“With all of the supply chain issues we are facing now, it’s very bad timing to expose detailed records on transportation companies and individual drivers. The COVID 19 pandemic has hit the transportation sector extremely hard and highlights how the industry needs to transform and modernize. This data leak contained multiple risks of how criminals could use the privileged information to identify targets and establish a position of trust with their victims. Credit and debt information will always be a valuable target for traditional crimes and identity theft, but there are also a range of scams or fraud that are specific to the transportation industry. Unfortunately, this database contained enough information that bad actors could potentially use as a working list.”
Audio player loading… An unsecured database containing 822k records including 600k credit reports related to the US and Canadian transportation industry has been discovered online. Security researcher Jeremiah Fowler together with the Website Planet research team found the database which contained detailed information on trucking, transport companies and even individual…
Recent Posts
- The iOS 18.4 beta brings Matter robot vacuum support
- Philips Monitors is now offering a whopping 5-year warranty on some of its displays, including a gorgeous KVM-enabled business monitor
- The secretive X-37B space plane snapped this picture of Earth from orbit
- Beyond 100TB, here’s how Western Digital is betting on heat dot magnetic recording to reach the storage skies
- The end of an era? TSMC, Broadcom could tear apart Intel’s legendary business after 57 years by separating its foundry and chip design
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010