← Rapido

2024 Rapido — publicly reachable feedback / ticketing portal exposed rider and customer PII

2024 1.8K records affected Share on X

Data compromised

Full names, email addresses, and mobile numbers captured in feedback responses per TechCrunch and Indian national dailies

Technical writeup

Journalism in December 2024 described an open Typeform-linked feedback workflow for Rapido’s auto-rickshaw onboarding site that leaked roughly 1,800 submissions with names, emails, and phone numbers until researchers and reporters prompted a takedown—illustrating classic internet-exposed third-party SaaS coupling without payment-card fields but with clear social-engineering value.

Root cause

Misconfigured or insufficiently access-controlled third-party feedback / survey integration on a public web property

References