Tuesday , August 25 2026
Australian fintech

Australian fintech database exposed in 27000 records

Cybersecurity researcher Jeremiah Fowler recently revealed a sensitive data exposure involving the Australian fintech company Vroom by YouX, previously known as Drive IQ.

Fowler, in a report to Website Planet, found an unsecured Amazon S3 bucket with 27,000 records. This database contained sensitive personal information, such as driver’s licenses, medical records, employment statements, and bank details, without any password protection or encryption.

Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

A mysterious AI model dubbed "Ox Alpha" has surfaced online and created noise within the developer community after releasing on...
Read More
Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about...
Read More
After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
“Zombie Card” attack revels expired Visa card may be used for contactless payments

Critical Zimbra RCE Flaw Actively Exploited in the Wild

CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code...
Read More
Critical Zimbra RCE Flaw Actively Exploited in the Wild

The exposed data is concerning, showing bank statements with account and partial credit card numbers. Fowler also found an internal screenshot of a separate MongoDB instance containing 3.2 million documents.

This screenshot shows a bank statement document that includes account details, transaction activity, and PII of the account holder. Source: websiteplanet.com

Company’s Quick Response:

Fowler quickly reported the vulnerability to Vroom, which immediately limited public access to the database. The company recognized the issue and promised a post-incident review, emphasizing its seriousness.

“We’ve identified and resolved the issue causing this vulnerability, so thank you for bringing it to our attention,” the company stated.

Vroom, which launched in 2022 as Drive IQ, is an AI-based platform that simplifies vehicle financing by connecting customers with lenders. It analyzes customer and vehicle information to deliver pre-approved financing offers. However, records from 2022 to 2025 reveal concerns about the company’s management of sensitive customer data.

The exposed information, such as identity and financial documents, poses serious fraud risks, including social engineering, fake accounts, loan applications, and impersonation, according to Fowler. Partial credit card numbers can help fill in missing details through cross-referencing or phishing scams.

He suggested that fintech companies adopt stronger security measures, including end-to-end encryption, access controls, multi-factor authentication, and regular security audits. He also supports data minimization policies, recommending that companies “collect and store active data while deleting outdated records.”

Over 200 Million Info Leaked Online Allegedly Belonging to X

 

Check Also

Splunk

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as …