Powered by

Home Startup News Rapido Exposes User Data Due to Security Flaw in Feedback Form

Rapido Exposes User Data Due to Security Flaw in Feedback Form

Rapido, the popular ride-hailing unicorn, recently experienced a data breach after a security flaw in a feedback form exposed the personal information of its users and drivers.

By Mrigank Sharma
New Update
Rapido Exposes User Data Due to Security Flaw in Feedback Form

rapido, the ride-hailing unicorn operating in India, has reportedly exposed personal data of its users and drivers due to a security flaw in a third-party feedback form. 

The issue, which was discovered by security researcher and ethical hacker Renganathan P occurred when the feedback form, which was intended to collect user reviews, was hosted on a separate domain rather than Rapido's primary website. 

This oversight led to the unintentional exposure of sensitive information, including full names, phone numbers, and email addresses, belonging mostly to auto drivers using the platform, along with a few customers.

As of December 19, the feedback portal had more than 1,800 responses, with personal details accessible to anyone who stumbled upon the link. Renganathan highlighted that the form did not have proper access controls allowing unauthorized access to the data. 

Read more - Hair Care Brand Arata Secures $4 Mn In Series A Funding

He emphasized the importance of secure coding practices, especially when outsourcing work to external agencies, and recommended that companies perform regular security assessments and host bug bounty programs to prevent such breaches.

Rapido responded by fixing the issue after being contacted by TechCrunch, changing the portal settings to private. In a statement Rapido’s co-founder and CEO acknowledged the breach and explained that the survey links had inadvertently reached unintended users. 

The company also emphasized that the data leak happened during their efforts to collect feedback for improving their services.

Advertisment

This breach is part of a growing trend of data security issues affecting Indian startups. Recently fintech company Signzy and health insurer Star Health have also faced similar security incidents. 

As Indian companies continue to digitize and scale ensuring robust data protection measures will be crucial in preventing such breaches and maintaining user trust.

Want to go deeper into the world of startups and entrepreneurship? Check out these categories on VIESTORIES:

Startup Funding and StoriesDiscover Funding Trends and Stories Shaping Indian Startups.

Startup Funding NewsYour Gateway to Every Funding Update.

Latest Startup NewsStay updated with the latest startup news and trends. Your go-to source for startup ecosystem updates.

Startup StoriesDiscover inspiring tales of startups overcoming challenges and achieving success.

Advertisment