Home/Incidents/Vroom by YouX

Vroom by YouX

26 Mar 2025 · National · Finance & Insurance
Data Breach MEDIUM ✓ Verified

What happened

Independent cybersecurity researcher discovered an open, completely unauthenticated MongoDB database cloud instance operated by fintech automotive financier Vroom by YouX. The misconfigured container exposed thousands of consumer driver's licenses, bank verification files, and PII profiles for ~10 months.

Incident details

Organisation
Vroom by YouX
Date
26 Mar 2025
Attack type
Data Breach
Severity
MEDIUM
Sector
Finance & Insurance
State
National
Records affected
Unknown
Threat actor
Human Error

Source

cyberdaily.au ↗
← Back to all incidents