Rapido Data Leak: User and Driver Data Exposed

Rapido Addresses Data Exposure Incident
Rapido, a widely-used ride-hailing service in India, has resolved a security vulnerability that resulted in the unintentional disclosure of user and driver data, as first reported by TechCrunch.
Details of the Security Flaw
The vulnerability was identified by security researcher Renganathan P and centered around a web form designed for gathering feedback from Rapido auto-rickshaw operators and riders. This form inadvertently revealed full names, email addresses, and phone numbers, as confirmed by the researcher and observed by TechCrunch.
The exposed data stemmed from one of Rapido’s application programming interfaces (APIs). This API was intended to transmit information submitted through the feedback form to a third-party service utilized by the company.
Verification and Scope of the Exposure
TechCrunch independently confirmed the data exposure by submitting a test message via the feedback form. The submitted data was subsequently visible within the compromised portal.
As of Thursday, the exposed portal contained over 1,800 feedback submissions. A significant portion of these records included phone numbers associated with drivers, alongside a smaller number of email addresses, according to the researcher’s findings.
Potential Risks Associated with the Breach
The researcher cautioned that the exposed information could have been exploited for malicious purposes. This included potential large-scale social engineering attacks targeting drivers via phone calls, or the sale of the data on the dark web.
Rapido’s Response
Following notification by TechCrunch regarding the data leak, Rapido immediately restricted access to the exposed portal, making it private.
Official Statement from Rapido
Rapido CEO Aravind Sanka issued a statement to TechCrunch, explaining that the company routinely seeks feedback from its stakeholders through external parties. He acknowledged that survey links had inadvertently been accessed by unintended recipients.
Sanka characterized the collected phone numbers and email addresses as “non-personal in nature.” However, the exposed data clearly included personally identifiable information (PII) as demonstrated by the researcher and TechCrunch’s verification.
Here's a summary of the key points:
- A security flaw in Rapido’s feedback form exposed user data.
- The exposed data included names, email addresses, and phone numbers.
- Rapido has secured the portal after being alerted to the issue.
- The incident highlights the importance of data security in the ride-hailing industry.
Related Posts

NHS England Data Breach Confirmed by Tech Provider

Cisco Zero-Day Exploit: Chinese Hackers Targeting Customers

Pornhub Hacked: User Data Extorted by Hacking Group

Google and Apple Release Emergency Security Updates

700credit Data Breach: 5.6 Million Affected
