An error on the Ford Motor Company allowed third parties to access important systems and compromise sensitive data (customer databases, employee records, internal tickets, etc.).
The problem stemmed from a misconfiguration of the Pega Infinity customer engagement system running on Ford's servers.
See also: T-Mobile hacked; Hacker says he has stolen data of millions of customers

Data theft and account breaches
Security researchers recently uncovered a bug on Ford's website that allowed them to access confidential company files and databases, while also making it possible to compromise accounts.
The security issue is caused by CVE-2021-27653, a vulnerability that allows information disclosure in Pega Infinity customer management system instances that are not configured correctly.
The researchers shared with BleepingComputer several screenshots from Ford's internal systems and databases.
See also: #KartaGate: The Commissioner for Personal Data Protection confirms the breach
To exploit the vulnerability, an attacker would first need to gain access to the backend web panel of a malicious Pega Chat Access Group portal instance.
As BleepingComputer found, different payloads provided as URL arguments could allow attackers to execute queries, retrieve databases, OAuth access tokens, and perform administrator-level actions.

Researchers state that some of the exposed data contained sensitive personal information, including:
- Customer and employee records
- Account numbers
- Database names and tables
- OAuth access tokens
- Internal tickets
- User profiles within the organization
- Pulse actions
- Internal interfaces
The researchers say that exploiting the vulnerability could have significant consequences. “Attackers could use the identified vulnerabilities to obtain a large number of sensitive files, perform account takeover attacks, and obtain a significant amount of data,” one of the researchers wrote in a blog post.
The researchers had reported their findings to Pega as early as February 2021, and the vulnerability was patched relatively quickly.
The issue was also reported to Ford around the same time through the HackerOne.
However, researchers told BleepingComputer that communication with Ford was not the best:
“At some point, they stopped answering our questions altogether. It took HackerOne’s mediation to get a response regarding the vulnerability report,” researcher John Jackson told BleepingComputer.

It took months for the error to be publicly disclosed.
See also: Zoom to pay $85 million in privacy lawsuit
Currently, Ford's vulnerability disclosure program does not offer monetary incentives or bug bounties, so disclosing the issue in the public interest was the only "reward" the researchers were hoping for.
A copy of the disclosure report shared with BleepingComputer indicates that Ford declined to comment on specific safety-related actions.
It is not known whether a cybercriminal exploited the vulnerability to compromise Ford's systems or if sensitive customer data.
Source: Bleeping Computer
