The Ministry of Digital Affairs has blocked access to a database that contained the personal information of up to 100,000 iRent users, after it was found that the data were unprotected, a senior ministry official said yesterday.
The statement came after US Web site TechCrunch on Tuesday reported that a database containing iRent data “was inadvertently accessible from the Internet.”
It was on a cloud server owned by Taiwanese automotive conglomerate Hotai Motor Co, it said.
Photo: Cheng Wei-chi, Taipei Times
“Because the database was not password-protected, anyone on the Internet could access the iRent customer data just by knowing its IP address,” the report said.
The databank contained the names, mobile phone numbers, e-mail addresses, home addresses, drivers’ license photographs and partly redacted payment card information of customers of iRent, a vehicle rental and sharing platform.
TechCrunch said security researcher Anurag Sen discovered the exposed database, adding that it had reviewed part of it and confirmed Sen’s findings.
It said it sent several e-mails to Hotai Motor about the exposed database, but did not receive a reply.
It said it also contacted the ministry, which took action to deal with the situation.
Deputy Minister of Digital Affairs Lee Huai-jen (李懷仁) confirmed that Minister of Digital Affairs Audrey Tang (唐鳳) was informed about the exposed databank by a foreign media organization during the Lunar New Year holiday.
Tang referred the case to the Taiwan Computer Emergency Response Team Coordination Center, a unit operated by the ministry-affiliated Taiwan Network Information Center, because it was an information security incident involving a private company, Lee said.
The center blocked outside access to the database, he added.
Hotai Motor’s mobile services unit said in a statement that it had addressed the exposed database “at the first moment” and reinforced its security.
A full-scale check of related systems and an investigation into the case shed light on the possible impact of the data spillage, the company said, without elaborating.
Security checks on the iRent system have been conducted regularly, it said, adding that iRent transactions are protected under the Secure Sockets Layer protocol.
Chinese-language media reported that iRent has nearly 1.4 million members and that the company hopes to raise that number to 1.8 million this year, while increasing the number of vehicles from 2,000 to 9,000.
The TechCrunch report cited Sen as saying that the exposed database contained millions of partial credit card numbers and at least 100,000 customer identification documents, as well as selfies, signatures and rental vehicle details.
It also said the database had been unprotected since May last year, adding that it was unclear whether any unauthorized party had accessed it.
A group of Taiwanese-American and Tibetan-American students at Harvard University on Saturday disrupted Chinese Ambassador to the US Xie Feng’s (謝鋒) speech at the school, accusing him of being responsible for numerous human rights violations. Four students — two Taiwanese Americans and two from Tibet — held up banners inside a conference hall where Xie was delivering a speech at the opening ceremony of the Harvard Kennedy School China Conference 2024. In a video clip provided by the Coalition of Students Resisting the CCP (Chinese Communist Party), Taiwanese-American Cosette Wu (吳亭樺) and Tibetan-American Tsering Yangchen are seen holding banners that together read:
UNAWARE: Many people sit for long hours every day and eat unhealthy foods, putting them at greater risk of developing one of the ‘three highs,’ an expert said More than 30 percent of adults aged 40 or older who underwent a government-funded health exam were unaware they had at least one of the “three highs” — high blood pressure, high blood lipids or high blood sugar, the Health Promotion Administration (HPA) said yesterday. Among adults aged 40 or older who said they did not have any of the “three highs” before taking the health exam, more than 30 percent were found to have at least one of them, Adult Preventive Health Examination Service data from 2022 showed. People with long-term medical conditions such as hypertension or diabetes usually do not
POLICE INVESTIGATING: A man said he quit his job as a nurse at Taipei Tzu Chi Hospital as he had been ‘disgusted’ by the behavior of his colleagues A man yesterday morning wrote online that he had witnessed nurses taking photographs and touching anesthetized patients inappropriately in Taipei Tzu Chi Hospital’s operating theaters. The man surnamed Huang (黃) wrote on the Professional Technology Temple bulletin board that during his six-month stint as a nurse at the hospital, he had seen nurses taking pictures of patients, including of their private parts, after they were anesthetized. Some nurses had also touched patients inappropriately and children were among those photographed, he said. Huang said this “disgusted” him “so much” that “he felt the need to reveal these unethical acts in the operating theater
Heat advisories were in effect for nine administrative regions yesterday afternoon as warm southwesterly winds pushed temperatures above 38°C in parts of southern Taiwan, the Central Weather Administration (CWA) said. As of 3:30pm yesterday, Tainan’s Yujing District (玉井) had recorded the day’s highest temperature of 39.7°C, though the measurement will not be included in Taiwan’s official heat records since Yujing is an automatic rather than manually operated weather station, the CWA said. Highs recorded in other areas were 38.7°C in Kaohsiung’s Neimen District (內門), 38.2°C in Chiayi City and 38.1°C in Pingtung’s Sandimen Township (三地門), CWA data showed. The spell of scorching