Independent cybersecurity researcher discovered an open, completely unauthenticated MongoDB database cloud instance operated by fintech automotive financier Vroom by YouX. The misconfigured container exposed thousands of consumer driver's licenses, bank verification files, and PII profiles for ~10 months.