SimpleTire left 2.8 million customer records in an open database
- Organization
- SimpleTire
- Exploit
- Misconfiguration
- Industry
- Retail
SimpleTire, a Pennsylvania online tire retailer, left a one terabyte database accessible on the internet without a password, exposing 2,808,697 records tied to customer orders.
Security researcher Jeremiah Fowler found the datastore and reported it through Website Planet. The bulk of the contents was order paperwork: 1,189,151 order confirmations stored as PDF files. Those documents carried customer names, phone numbers, physical addresses and partial payment card numbers with expiration dates.
The database held more than receipts. Fowler said it also contained references to authorized installers, return and refund requests, wholesale pricing records, receipt and product details, payment amounts, and images used on the company's website and in its email campaigns.
Fowler said he sent responsible disclosure notices to several company addresses and received no reply, and that the database stayed publicly reachable for more than three weeks after his discovery before access was finally restricted. How long it had been open before he found it was not established.
The researcher noted that the level of detail in the order confirmations would let a fraudster reference a genuine purchase when contacting a customer, making a request for updated payment details more convincing. SimpleTire did not issue a public statement about the exposure when the findings were published at the end of May 2023.