Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Tata Motors Data Leak – 70+ TB of Sensitive Info and Test Drive Data Exposed via AWS Keys

Security researcher Eaton Zveare has disclosed critical vulnerabilities in Tata Motors’ systems that exposed over 70 terabytes of sensitive data, including customer personal information, financial reports, and fleet management details.

Security researcher Eaton Zveare has disclosed critical vulnerabilities in Tata Motors’ systems that exposed over 70 terabytes of sensitive data, including customer personal information, financial reports, and fleet management details.

The flaws, uncovered during ethical hacking in 2023 but publicly shared only now, involved hardcoded AWS access keys on public-facing websites, granting unauthorized access to hundreds of cloud storage buckets.

This breach highlights ongoing risks in major automakers’ digital infrastructure, potentially compromising data on millions of customers and dealers.​

Tata Motors’ E-Dukaan platform, an e-commerce site for vehicle spare parts, contained plaintext AWS credentials directly in its source code, allowing anyone to access vast repositories of confidential files.

These keys unlocked customer database backups, lists with market intelligence, and hundreds of thousands of invoices revealing personal details like names, addresses, and Indian PAN numbers.

One bucket alone held about 40 GB of admin order reports, underscoring the sheer volume of exposed commercial data. Zveare noted that the keys were used merely to fetch a small 4 KB tax codes file, a minimal justification for such extensive risks.​

One bucket alone held about 40 GB of admin order reports, underscoring the sheer volume of exposed commercial data.
Madison Drake · Thehackingpost

Decryptable Credentials in FleetEdge System

A similar issue plagued FleetEdge, Tata’s fleet tracking solution, where AWS keys appeared encrypted in API responses but were easily decrypted via client-side code.

This “pointless” encryption, akin to recent flaws at Intel, exposed another trove of buckets, including a datalake with over 70 TB of fleet insights dating back to 1996.

Attackers could not only download historical vehicle data but also upload malware to connected websites, amplifying the threat to operational security. The discovery emphasized poor key management practices in client-facing applications.

Compounding the risks, E-Dukaan’s code included a backdoor to Tableau dashboards, enabling passwordless logins as any user, including the server admin, via a “trusted token” mechanism.

Advertisement

This granted full access to internal projects, financial reports, dealer scorecards, and data on over 8,000 users. Separately, an exposed Azuga API key in the test drive website’s JavaScript compromised fleet management for demonstration vehicles, potentially revealing real-time location tracking. Zveare halted deeper probes to avoid data exfiltration, confirming no malicious activity during testing.​

The vulnerabilities were reported through India’s CERT-In on August 8, 2023, but remediation dragged on until January 2024 amid repeated follow-ups. Tata Motors confirmed fixes in 2023 without notifying affected parties, raising questions about transparency.

As India’s largest automaker, operating in 125 countries, such lapses erode trust in data handling for vehicle owners. Experts urge enhanced code reviews and secret rotation to prevent future exposures.​

Follow us on Google News , LinkedIn , and X for daily cybersecurity updates. Contact us to feature your stories.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories