Cybersecurity researchers have uncovered a major data breach, affecting almost 300,000 taxi passengers in the UK and Ireland.

Jeremiah Fowler , working with vpnMentor, found a database containing personal information such as names, phone numbers, and email addresses . The database was not password protected , meaning all personal information was exposed. These files belong to Dublin-based iCabbi
The exposed database contained 22,745 files and .csv documents with customer, emails, phone numbers, and user IDs. The emails were associated with various providers and private domains, including: 117,231 Gmail, 65,060 Hotmail, 17,588 Yahoo, 18,099 iCloud, 12,798 Outlook; 7,484 Live, and more.
See also: AT&T: Data breach ultimately affects 51 million customers
Additionally, email addresses from universities, media outlets, and government agencies such as the BBC, NIH, Treasury, and Department of Justice have been exposed.
“The exposure of names, email addresses, phone numbers and user IDs opens Pandora’s box, bringing potential security issues, from identity theft to targeted phishing attacks,” said Javvad Malik, an executive at KnowBe4.
“The inclusion of high-profile individuals – from legislators to senior policy advisors and EU ambassadors – increases the risk, introducing possible avenues for more sophisticated social engineering and espionage attempts“.
Upon further investigation, Fowler found that the database served as a storage place for various documents used by the app. While not all of the documents were publicly accessible, cybercriminals can use the information exposed in this data breach to carry out various scams against taxi passengers.
See also: Epilepsy Foundation (EFMNY): Ransomware attack and data breach
Fowler immediately notified iCabbi about the issue. The company acknowledged the flaw and quickly deleted the exposed files.
“It’s refreshing to see that iCabbi responded so well to this report,” said Adam Pilton, cybersecurity consultant at CyberSmart.

Protecting companies from data breaches
One of the most effective practices for protecting corporate data is the use of advanced security solutions, such as firewalls and intrusion detection systems. These tools can detect and repel attacks before they can cause damage.
Additionally, training staff on information security issues is crucial. Employees must be aware of the risks associated with data security and how to avoid attacks
See also: GHC-SCW: Ransomware attack and patient data breach
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Using least privilege access policies is also an effective practice. This means that users only have access to the data and applications they need to perform their tasks.
Finally, regularly backing up data and implementing disaster recovery plans can help businesses recover quickly in the event of a data security breach.
Source: www.infosecurity-magazine.com
