Ecosystem

Tata Motors' 70TB Data Leak Reveals Critical AWS Security Failures

A security researcher uncovered multiple exposed AWS credentials at the Indian automaker, granting unrestricted access to decades of customer and operational data across hundreds of cloud storage buckets.

·3 min read
Tata Motors Breach Exposed 70TB of Sensitive Data Before Fix
Tata Motors Breach Exposed 70TB of Sensitive Data Before Fix

Tata Motors, the Indian automotive manufacturer, suffered a significant data exposure affecting over 70 terabytes of sensitive information due to multiple critical security oversights, according to findings by security researcher Eaton Zveare.

Zveare's investigation revealed that two separate sets of Amazon Web Services (AWS) credentials were left unprotected across Tata Motors' digital infrastructure, providing full access to hundreds of S3 buckets. The compromised data encompassed customer invoices, financial records, internal monitoring systems, and dealer performance analytics.

Exposed keys put data at risk

The first vulnerability appeared on E-Dukaan, Tata Motors' online marketplace for vehicle components, where AWS access credentials were hardcoded in plain text within the platform's code. This misconfiguration granted complete access to internal storage systems holding backup files, billing records, and customer information including Permanent Account Numbers (PANs), a critical government-issued identifier in India.

A separate issue emerged in FleetEdge, the company's fleet management platform, where a second pair of AWS keys was stored with client-side encryption that could be rapidly decoded using JavaScript. This exposure unlocked what Zveare termed a "massive" 70TB repository of fleet tracking and analytical information spanning more than two decades, with records dating back to 1996.

Tableau and API backdoors

Zveare's examination also uncovered a security flaw in Tata Motors' Tableau analytics infrastructure that allowed unauthenticated entry through token spoofing. By impersonating a legitimate user, he obtained administrative access to dashboards and reporting tools used by over 8,000 employees, exposing confidential business metrics and dealer information.

Additionally, an Azuga API credential was discovered embedded in JavaScript code on Tata's vehicle test-drive booking website. This key granted access to fleet management systems capable of tracking the real-time location of company vehicles.

Slow fix, serious lessons

Zveare disclosed all four security gaps to India's Computer Emergency Response Team (CERT-In) in August 2023. Tata Motors began remediation efforts following the report, though the company required several months to fully resolve the issues.

The automaker's communications head, Sudeep Bhalia, stated that all vulnerabilities were "promptly and fully addressed," and that the company's systems undergo regular security assessments by major cybersecurity firms. To date, Tata Motors has not publicly disclosed whether customers affected by the exposure have been informed.

The incident underscores how unprotected credentials and inadequate access management can compromise even large multinational corporations, offering important lessons for enterprises managing confidential customer information.

The breach also coincides with the emergence of a dataset containing 183 million exposed credentials that surfaced online, affecting numerous Gmail users and raising broader security alarms across the industry.