2024 Rapido — publicly reachable feedback / ticketing portal exposed rider and customer PII
Data compromised
Full names, email addresses, and mobile numbers captured in feedback responses per TechCrunch and Indian national dailies
Technical writeup
Journalism in December 2024 described an open Typeform-linked feedback workflow for Rapido’s auto-rickshaw onboarding site that leaked roughly 1,800 submissions with names, emails, and phone numbers until researchers and reporters prompted a takedown—illustrating classic internet-exposed third-party SaaS coupling without payment-card fields but with clear social-engineering value.
Root cause
Misconfigured or insufficiently access-controlled third-party feedback / survey integration on a public web property
References
- https://techcrunch.com/2024/12/19/indias-rapido-exposed-user-and-driver-data-through-leaky-website-feedback-form/
- https://timesofindia.indiatimes.com/technology/tech-news/researcher-claims-rapido-exposed-customers-data-heres-what-the-company-has-to-say/articleshow/116492017.cms
- https://indianexpress.com/article/technology/tech-news-technology/rapido-security-flaw-exposed-personal-data-9736077/