Hyundai Motor India fixes bug that exposed customers’ personal data

Hyundai’s India subsidiary has fixed a bug that exposed its customers’ personal information in the South Asian market.

TechCrunch reviewed a portion of the exposed data that included the registered owner name, mailing address, email address, and phone number of Hyundai Motor India customers who have serviced their vehicles at any of the company’s authorized service stations across India. The bug also disclosed vehicle details, including the registration number, color, engine number, and mileage covered.

In a phone conversation on Thursday, Hyundai Motor India spokesperson Siddhartha P. Saikia said the company would provide a statement. When shared by email, the statement said:

“We understand the importance of safeguarding the data of our customers and accordingly strive to create robust systems and processes. Further, these systems get periodically reviewed and updated based on needs. The Repair Order/Invoice link is shared only on the mobile number registered by the customer, once they have opted in to receive such updates. These are system-generated links without any human involvement. Hyundai assures continued efforts to safeguard the interest of the customers.”

Hyundai Motor India did not answer questions about whether it had the technical means, such as logs, to determine any improper access to a customer’s records, nor would the company say if any bad actors exploited the issue.

Security researcher Ashutosh, who preferred not to be named in full, shared the details about the simple bug with TechCrunch. The bug exposed the customer’s personal information through the web links Hyundai Motor India shared with customers over WhatsApp after receiving their vehicles for servicing at an authorized service station.

The web links that redirected customers to the repair orders and invoices in PDF files contained the customer’s phone number. A malicious actor could expose the information of other customers by changing the phone number in the link.

TechCrunch confirmed the researcher’s findings and emailed Hyundai Motor India on December 29. The company responded on January 4. TechCrunch shared the details of the bug with Hyundai Motor India on the same day, and requested Hyundai Motor India fix the bug within seven days due to its simplicity and severity. Hyundai Motor India fixed the bug on Thursday.

Upon receiving the company’s response, TechCrunch confirmed the bug was fixed, and the links in concern were no longer active — redirected to a page giving an error message.

Established in 1996, Hyundai Motor India is among the top three carmakers in the country, alongside Maruti Suzuki and Tata Motors. Hyundai Motor India has a network of over 1,500 service stations in the country. In May, the carmaker announced an investment of $2.45 billion (200 billion Indian rupees) over the next 10 years in the southern Indian state of Tamil Nadu to bolster its plans for electric vehicles.