[ad_1]

An incorrectly configured cloud server used by BMW was found to have left sensitive internal data, including private keys, openly accessible online, a discovery made by a cybersecurity researcher indicates.
Security researcher Can Yoleri from SOCRadar stumbled upon the poorly configured cloud server of BMW during a routine internet scan.
Yoleri explained that the Microsoft Azure-hosted server utilized by BMW’s development team was mistakenly set to be publicly accessible due to a misconfiguration. As a result, it contained sensitive script files with access information and keys.
According to the evidence provided to TechCrunch, this data included private access keys to BMW’s cloud infrastructure across several regions such as China, Europe, and the US, and credentials to internal BMW databases.
The duration and extent of the data exposure remain uncertain. Yoleri noted that only the owner of the cloud server could determine the length of exposure.
BMW representative Chris Overall confirmed to TechCrunch via email that the breach had taken place in an Azure bucket within their storage development space but clarified that no customer or personal information had been compromised.
Overall stated that the issue was addressed at the onset of 2024. Despite the fix, BMW has yet to comment on the longevity of the exposure or whether any unauthorized parties accessed the information.
According to Yoleri, after warning BMW about the exposure, the company secured the server but did not update the compromised credentials, a critical step that remains unaddressed. Attempts to bring this to BMW’s attention went unanswered, Yoleri claimed.
The report also referenced a similar incident in the previous month with Mercedes-Benz, who exposed a volume of internal data due to an accessible private key online. After TechCrunch contacted them about the breach, Mercedes-Benz took immediate action to secure their system.
[ad_2]
FAQs about BMW’s Security Breach
- What was the nature of the data exposed in BMW’s security breach?
Sensitive data, including server private keys and login credentials to BMW’s development and production databases, was left accessible on an improperly configured cloud server. - Has BMW taken any actions in response to this breach?
BMW has secured the cloud server in question by making it private. However, the company is yet to update the compromised credentials that were exposed. - Were any customers’ personal data compromised in the breach?
According to BMW, no customer or personal data was affected by this security lapse. - How long was BMW’s cloud server data exposed to the public?
The exact duration of the public exposure remains unknown, as only BMW has the means to determine the length of time their data was unprotected. - How was the breach discovered?
The security lapse was found by Can Yoleri of SOCRadar during routine scans of the internet for exposed cloud servers.
Conclusion
The recent discovery of a security lapse at BMW highlights the ongoing challenges companies face in securing their online infrastructure. Despite the swift action to secure the exposed cloud server, crucial steps such as updating compromised access credentials have been overlooked. This incident serves as a crucial reminder for organizations to maintain rigorous security protocols and respond comprehensively to any potential breaches to protect against unauthorized access to sensitive information. The incident also underscores the importance of transparency and communication with the cybersecurity community when vulnerabilities are identified.










































