logo

From One File to Full Exposure: Vendor’s .git File Leaks Source Code, Secrets, and Over 1 Million PII Records of Automotive Giants

ID: 4fd2d7a7-659a-5a3c-bd4a-9e56ea2a3b11

STIX ID: report--4fd2d7a7-659a-5a3c-bd4a-9e56ea2a3b11

Feed Name: CloudSEK Blog

Threat Score
90/100

Date Published: 2025-08-14

Date Updated: 2026-04-27

...
...

CloudSEK's SVigil discovered a publicly accessible .git repository on a leading roadside assistance and insurance vendor, exposing ~20 GB of data including full source code, hardcoded SMTP/SMS/payment/cloud DB credentials, and PII/financial/identity documents for thousands of merchants and customers; this misconfiguration enabled trivial cloning with tools like Git Dumper and posed high-risk threats such as phishing, unauthorized transactions, identity theft, and large-scale data compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.