The personal information of millions of American motorists who sign up to the roadside assistance program provided by the drivesure company is being made available online after a cybercriminal hacked the firm and dumped a variety of sources of its databases on forums for hackers. A security researcher from the vendor Risk Based Security discovered the raidforums database on the cracking forums that were due to expire in the month of March and informed Drivesure of the issue this week. The databases include names, deals with cell phone volume, electronic mails. They also include data on the customers’ vehicles which includes their produce, model and VIN number along with service records and damage claims. The breach also contained more than 93,000 bcrypt hashed passwords which are generally used to protect data stored by an application that is secure. These passwords are susceptible to brute force attacks if a hacker spends days running scripts on them.
Drivesure is a company that helps car dealerships build customer loyalty by leveraging information about their interactions with customers. The company is based in Illinois and focuses on retention of employees and consumer training programs, among others.
Thompson exploited an redirected here issue with the cloud firewall configuration to bypass security measures in place at the company and gain access to folders and data buckets. She then uploaded the stolen data to GitHub and then gradually updated the information as she continued to hack. It is unclear if she intended to make a profit from her attack. In the last few weeks, other high-profile targets were also targeted. These included Washington State unemployment claimants whose claims were affected by a security breach that occurred in a third-party service utilized by an auditor and employees of the air charter company Solairus Aviation.


