Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Are you okay?

    April 28, 2026

    Pope Leo Issues Damning Description Of Those Who Wage War

    April 28, 2026

    How to Get Soy Sauce Out of Clothes. What Actually Works

    April 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Are you okay?
    • Pope Leo Issues Damning Description Of Those Who Wage War
    • How to Get Soy Sauce Out of Clothes. What Actually Works
    • U.S. Government Will Stop Paying for Test Strips to Detect Deadly Drugs
    • Technbrains – Company Profile – AllBusiness.com
    • Air Travel Safety: ER Doctor Warns Against These 2 Mistakes
    • Talk Your Book: Consternation About Concentration
    • Live Updates: Gunman Who Charged at Washington Press Gala Faces Arraignment
    Facebook X (Twitter)
    SBM Global News
    Demo
    • Home
    • Top Stories
      • Politics
    • Business
      • Small Business
      • Marketing
    • Finance
      • Investment
    • Technology

      Technbrains – Company Profile – AllBusiness.com

      April 28, 2026
      Read More

      Truecaller faces mounting pressures as its growth matures

      April 27, 2026
      Read More

      OpenAI CEO apologizes to Tumbler Ridge community

      April 26, 2026
      Read More

      Porsche is adding an all-electric Cayenne coupe to its lineup

      April 24, 2026
      Read More

      Jahid Babu Tech – Company Profile

      April 24, 2026
      Read More
    • Lifestyle
      • Travel
    • Feel Good
    • Get In Touch
    SBM Global News
    Demo
    Home»Technology»Bugs in transportation app Moovit gave hackers free rides
    Technology

    Bugs in transportation app Moovit gave hackers free rides

    By Staff WriterAugust 14, 20233 Mins Read
    Facebook Twitter LinkedIn Reddit Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers could have hijacked the user accounts of a popular transportation app and used them to get free rides and access people’s personal information, according to a security researcher.

    Omer Attias, a security researcher at SafeBreach, said he found three vulnerabilities in the Moovit app, which allowed him to collect new Moovit user’s registration information from all over the world — including cell phone numbers, email addresses, home addresses, and the last four digits of credit cards. Worst of all, the bugs could have allowed him to take over other people’s accounts, and consequently their credit cards, to pay for his own rides.

    This whole chain of exploits could have been performed without the target ever finding out, apart from seeing unwanted charges on their credit card. Attias called it “the perfect attack.”

    “We can fully impersonate accounts, without disconnecting them. It’s crazy, we actually have the ability to perform all the operations on behalf of different accounts, including ordering train tickets,” Attias told TechCrunch in an interview ahead of his talk at the Def Con hacking conference in Las Vegas. “And additionally, we can access all of their personal information.”

    To demonstrate the impact of the bugs he found, Attias created a custom interface that allowed him to take over other people’s accounts with a couple of taps. And while Attias said he tested his exploits only in Israel, he said he thinks it could have worked in other cities given that Moovit operates all over the world.

    Moovit is an Israeli startup that was acquired by Intel in 2020 for $900 million. The app allows users to find routes and view public transportation systems’ maps, as well as to purchase and use tickets. The app and its underlying technology are widely used worldwide: Moovit claims to serve 1.7 billion riders in 3,500 cities across 112 countries.

    While the impact of these vulnerabilities was potentially massive, Moovit said there is no evidence that malicious hackers found and exploited these bugs. Attias said that he reported all the bugs he found to the company in September 2022, and the company subsequently fixed them.

    “Moovit was aware of and rectifying the issue when it was reported, and took immediate steps to finish correcting the issue,” Moovit spokesperson Sharon Kaslassi told TechCrunch. “The vulnerabilities have long since been fixed and no customer action is required. It’s important to note that no bad actors took advantage of these issues to access customer data. Additionally, no credit card information was exposed as Moovit and Moovit-Pango do not keep credit card information on file.”

    Kaslassi also said that “ticketing service relevant to these findings is active in Israel only.”

    “According to our records, neither Safebreach or anyone else took advantage of any customer data in or outside of Israel,” the spokesperson added.

    In response to Moovit’s comments, Attias said that he and his colleagues “believe we could have charged any customer not limited to Israeli customers. We haven’t seen any differentiator between Israeli and non Israeli customers in their API requests.”

    Read more from Black Hat:

    • How the FBI goes after DDoS cyberattackers
    • Researchers watched 100 hours of hackers hacking honeypot computers
    • Researchers jailbreak a Tesla to get free in-car feature upgrades

    Originally published at techcrunch.com

    devices gadgets notebooks phones tablets technology
    Share. Facebook Twitter LinkedIn Email Reddit
    Previous ArticleSaudi Arabia Appoints Envoy to Palestinians Amid Push for Ties With Israel
    Next Article Alibaba is doubling down on A.I. — Chinese stocks to watch

    Related Posts

    Technbrains – Company Profile – AllBusiness.com

    April 28, 2026
    Read More

    Truecaller faces mounting pressures as its growth matures

    April 27, 2026
    Read More

    OpenAI CEO apologizes to Tumbler Ridge community

    April 26, 2026
    Read More
    Add A Comment

    Leave A Reply Cancel Reply

    Demo
    Top Posts

    Former FBI, CIA Head Has ‘Serious Concerns’ With Trump Cabinet Picks

    December 28, 2024435

    Emirates to operate next-gen A350 on the third daily service to Cape Town

    January 14, 2026256

    AAVE Price Prediction: Target $215-225 by Mid-January 2025 as Technical Indicators Signal Bullish Momentum

    December 15, 2025240

    Ventive Hospitality Joins Green Fins: Strong ESG Lift

    February 17, 2026211
    Don't Miss
    Investment

    Are you okay?

    By Staff WriterApril 28, 20267 Mins Read

    “Don’t make me stop this car!” I roared at the kids in the back. And…

    Read More

    Pope Leo Issues Damning Description Of Those Who Wage War

    April 28, 2026

    How to Get Soy Sauce Out of Clothes. What Actually Works

    April 28, 2026

    U.S. Government Will Stop Paying for Test Strips to Detect Deadly Drugs

    April 28, 2026
    Stay In Touch
    • Facebook
    • Twitter
    Demo
    About Us

    Small Business Minder brings together business and related news from around the world in one place. Follow us for all the business news you'll need.

    Facebook X (Twitter)
    Our Picks

    Are you okay?

    April 28, 2026

    Pope Leo Issues Damning Description Of Those Who Wage War

    April 28, 2026
    Most Popular

    Former FBI, CIA Head Has ‘Serious Concerns’ With Trump Cabinet Picks

    December 28, 2024435

    Emirates to operate next-gen A350 on the third daily service to Cape Town

    January 14, 2026256
    © 2026 Small Business Minder
    • Home
    • Get In Touch

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. To get the most from our site, please disable your Ad Blocker.