HomeNewsTechnologyExclusive: Flaw left user data of 2 million Bounceshare customers vulnerable to hack

Exclusive: Flaw left user data of 2 million Bounceshare customers vulnerable to hack

Bounceshare has fixed the bug that put a user base of approximately 2 million users at risk of getting their information leaked on the web.

November 13, 2019 / 13:02 IST
Story continues below Advertisement

With the government encouraging vehicle sharing and carpooling, new services have begun which allow people to hire vehicles as per their demand. One of them is Bounceshare, which offers users the ability to book a scooter in their vicinity, use it for their commute and later drop it off at their destination.

However, recently, a digital flaw was uncovered in the Bounceshare app by security researcher Ehraz Ahmed. One of its Internal Application Programming Interface (API) can log the hacker into any Bounceshare account, bypassing the users’ phone number into the request, and in response, it returns with the Access Token, and RiderId. This Access Token can then be used to access any Bounceshare account.

Story continues below Advertisement

Bounceshare's user base of approximately 2 million users was at risk of getting their information leaked on the web.  Hackers and Telemarketers can mine its data by automating a script using a phone number dump found online.

The vulnerability could also have allowed hackers to access the users’ Bounceshare account and their sensitive information, such as Driving License, selfies, phone number, or their email addresses. If the user had linked his Paytm account, then it was also possible for the attacker to see the user's balance, and book rides from the user's account.