Holiday goers beware: Global car rental service data leak exposes thousands of drivers
Did you rent a car recently?

Image by Cybernews.
- Carla exposed about 48,000 car rental confirmation PDFs through an unsecured AWS bucket.
- The leaked files included names, emails, phone numbers, booking numbers, rental dates, costs, and locations.
- Cybernews researchers found no evidence of misuse, and Carla restricted public access after being notified.
- The data could help scammers target travelers with convincing fraud or identify when homes may be empty.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Carla, a global car rental services aggregator, leaked tens of thousands of files, revealing personal customer details. Threat actors may exploit leaked data to uncover users’ travel patterns and target them with convincing spam.
With the summer approaching its mid season, millions of business travelers and vacationers rent cars to get the most out of their precious time off. However, a fun trip can have some unintended consequences, for example, leaked personal details.
On June 3rd, 2026, Cybernews researchers uncovered an exposed cloud storage bucket with 48,000 PDF files, most of which revealed car rental details. According to the team, the exposed data belongs to Carla, a popular platform, which aggregates car rental options across 180 countries.
The exposed documents, mostly car rental confirmations, exposed everything from car rental dates to drivers’ personal information. At the time of discovery, the datastore had several hundred new additions per day, hinting the bucket was used to store recent information.
“Individuals impacted by the Carla data leak may face a heightened risk of social engineering attacks. Moreover, malicious actors can use the exposed rent period data to deduce individuals’ travel patterns,” the team explained.
After our researchers reached out to the company, Carla’s bucket was no longer publicly accessible. The team did not notice any indication the data was exploited. However, if our team uncovered it, so too may have threat actors that have automated tools searching specifically for unprotected corporate data.
What details Carla data leak exposed?
According to the team, the exposed information was stored on an unprotected Amazon Web Services (AWS) bucket. The exposed bucket contained nearly around 48k documents, covering confirmation that users receive after successfully booking a vehicle.
The exposed documents revealed:
- Voucher, confirmation numbers
- Personal driver data with full names, email addresses, phone numbers
- Rent period, cost, pick-up and drop-off locations
- General vehicle information, sometimes model, transmission mode, size, etc.
Malicious actors could abuse this type of information to target exposed individuals with convincing social engineering attacks. One popular tactic scammers use is to send convincing emails about a supposedly canceled service right before the planned trip.
The expectation is that panicked holiday goers will miss telltale signs of a scam and will be more likely to reveal financial details or enter credit card information in an attempt to avoid problems with their vacation time.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Other attackers could utilize leaked information to understand users’ travel patterns and attempt to use other data leaks to find individuals' home addresses. In these cases, attackers could try to physically rob empty houses.
Carla, a Turkey-based company, provides car rental aggregation software, spanning over 20,000 locations in 180 countries. The company claims to have around 2M users annually, as well as 6,5M+ rentals annually.
Carla is not the first rental industry player exposing user details. Last year Cybernews researchers discovered that Rent Go, another Turkish car rental service, exposed data of over 160K customers.
Disclosure timeline
- Leak discovered: June 3rd, 2026
- Initial disclosure: June 3rd, 2026
- Leak observed closed: June 29th, 2026