La Malle Postale left data on about 90,000 hiking clients publicly exposed

Organization
La Malle Postale
Exploit
Misconfiguration
Industry
Transportation

La Malle Postale, a French company that transports luggage and passengers along walking routes including the Santiago de Compostela pilgrimage trails, left a database of client records open on the internet without a password.

Researchers at Cybernews said they found the datastore on January 11, 2023. It held more than 4GB of data covering roughly 90,000 customers, including names, email addresses and phone numbers.

The exposed material went well beyond contact details. It contained more than 13,000 SMS messages exchanged between the company and its clients, credentials for about 70,000 customer accounts, and employee and administrator credentials along with authentication tokens and password salts. The customer passwords were hashed, but the researchers said the WordPress MD5 and phpass scheme used to protect them is considered weak and straightforward to crack.

According to the research team, repeated disclosure attempts went unanswered. Access to the datastore was finally closed at the end of April 2023, more than three months after the researchers first tried to reach the company.

The findings were published in May 2023. La Malle Postale did not reply to the researchers, and whether anyone else reached the data during the months it sat open was never established.

Sources