HomeTechnologyTata Motors fixes major data leak that exposed customer details, internal reports, and 70TB of company data online

Tata Motors fixes major data leak that exposed customer details, internal reports, and 70TB of company data online

Tata Motors fixed major security flaws in its E-Dukaan portal that exposed customer data, invoices, and internal reports. Researcher Eaton Zveare discovered the vulnerabilities, which have since been patched.

October 29, 2025 / 13:40 IST
Story continues below Advertisement
Tata Motors
Tata Motors

Tata Motors has fixed multiple security loopholes that had exposed sensitive customer information and internal company data online. The issues, discovered by cybersecurity researcher Eaton Zveare, were found in the automaker’s E-Dukaan platform, a digital storefront for ordering spare parts for Tata’s commercial vehicles.

According to Zveare’s findings shared with TechCrunch, the E-Dukaan web app contained hardcoded private keys for Tata Motors’ Amazon Web Services (AWS) account. This misstep potentially gave anyone access to the company’s cloud storage, where large volumes of confidential data were stored.

Story continues below Advertisement

Among the exposed information were hundreds of thousands of invoices, complete with customer names, addresses, and even Permanent Account Numbers (PANs). The leak also included database backups, internal documents, and communication files.

Even more alarming was the access to over 70 terabytes of data related to Tata’s FleetEdge vehicle tracking software — the same system that collects live data from commercial vehicles. Zveare also found administrator-level credentials for a Tableau analytics dashboard that contained reports on more than 8,000 users, including internal performance and financial data.