[[{“value”:”
Ride hailing unicorn Rapido reportedly leaked the personal information of its users and drivers due to a security issue with a feedback form.
The personal data was exposed due to a flaw with a website form which collected feedback from Rapido rickshaw users and drivers. The issue was discovered by security researcher and ethical hacker Renganathan P, TechCrunch reported.
Rapido collected the user data via a third-party feedback form, which exposed the full names, email addresses, and phone numbers, as per the report.
As of Thursday (December 19), the open portal had more than 1,800 feedback responses which consisted of phone numbers of rickshaw drivers and a comparatively fewer email addresses.
A mail sent to Rapido seeking details about the development didn’t elicit any response till the time of publishing this story. However, the TechCrunch report said that Rapido fixed the issue by changing the portal settings to private after it was contacted by the publication.
“As a standard operating procedure, we are in the process of soliciting valuable feedback from our stakeholder community on our services. While this is being managed by external parties, we have come to understand that the survey links have reached some unintended users from the public,” Rapido cofounder and CEO told the publication in a statement.
Founded in 2015 by Rishikesh SR, Pavan Guntupalli, and Aravind Sanka, Rapido primarily operates in the bike taxi and auto transportation segments. It also entered the cab services segment recently.
The startup trimmed its loss by more than 45% to INR 370 Cr in the financial year 2023-24 (FY24) from INR 675 Cr in the previous year. Revenue zoomed 1.5X to INR 648.1 Cr from INR 443 Cr in FY23.
The development comes at a time when a number of Indian startups and companies have been hit by data security troubles in recent times. Fintech SaaS startup Signzy was hit by a cyberattack in late November.
Prior to that, health insurer Star Health was caught in a data breach and the data of its customers was allegedly put up for sale on instant messaging app Telegram. The company said that the hacker, who leaked the personal data of its 3 Cr customers, demanded a ransom of $68,000 (INR 57 Lakh).
In September, payments and commerce platform DotPe also leaked data of its customers due to a “human error”.
The post Rapido Leaks Info Of Users, Drivers Due To Security Flaw appeared first on Inc42 Media.
“}]]
Read More
Latest Startup News From The Indian Startup Ecosystem – Inc42 Media
