By using this site, you agree to the Privacy Policy and Terms of Use.
Accept

News Junction

Notification Show More
Font ResizerAa
  • Home
  • World News
    World NewsShow More
    Ousted Bangladesh PM Hasina’s party barred from election as party registration suspended
    Ousted Bangladesh PM Hasina’s party barred from election as party registration suspended
    May 14, 2025
    Cassandra Ventura testifies, tells jury freak offs became a job
    Cassandra Ventura testifies, tells jury freak offs became a job
    May 13, 2025
    White South Africans arrive in US after Trump administration granted them refugee status | World News
    White South Africans arrive in US after Trump administration granted them refugee status | World News
    May 13, 2025
    Trump’s Mideast Wish List: + Trillion in Investments – and Some Diplomacy Too
    Trump’s Mideast Wish List: $1+ Trillion in Investments – and Some Diplomacy Too
    May 13, 2025
    Djokovic-Murray coaching partnership ends before French Open | Tennis News
    Djokovic-Murray coaching partnership ends before French Open | Tennis News
    May 13, 2025
  • Business
    BusinessShow More
    Ukraine blows up bridges to consolidate its positions in Russia
    Ukraine blows up bridges to consolidate its positions in Russia
    August 18, 2024
    Commentary: AI phones from Google and Apple will erode trust in everything
    Commentary: AI phones from Google and Apple will erode trust in everything
    August 18, 2024
    The most famous Indian Dishes – Insights Success
    The most famous Indian Dishes – Insights Success
    August 18, 2024
    Life on the road as a female long rides cyclist
    Life on the road as a female long rides cyclist
    August 18, 2024
    UK inflation rises to 2.2%
    UK inflation rises to 2.2%
    August 18, 2024
  • Cryptocurrency
    CryptocurrencyShow More
    BTC, ETH, XRP, BNB, SOL, ADA, DOGE, PI, LEO, HBAR
    BTC, ETH, XRP, BNB, SOL, ADA, DOGE, PI, LEO, HBAR
    May 14, 2025
    Altcoins’ roaring returns and falling USDT stablecoin dominance suggest ‘altseason’ is here
    Altcoins’ roaring returns and falling USDT stablecoin dominance suggest ‘altseason’ is here
    May 14, 2025
    How to Use tsUSDe on TON for Passive Dollar Yield in 2025
    How to Use tsUSDe on TON for Passive Dollar Yield in 2025
    May 13, 2025
    South Korea’s Democratic Party sets up ‘Digital Asset Committee’
    South Korea’s Democratic Party sets up ‘Digital Asset Committee’
    May 13, 2025
    Curve DAO (CRV) price drops as Curve Finance battles DNS attack
    Curve DAO (CRV) price drops as Curve Finance battles DNS attack
    May 13, 2025
  • Technology
    TechnologyShow More
    How to Improve Your Spotify Recommendations
    How to Improve Your Spotify Recommendations
    August 18, 2024
    X says it’s closing operations in Brazil
    X says it’s closing operations in Brazil
    August 18, 2024
    Supermoon set to rise: Top tips for amateur photographers | Science & Tech News
    Supermoon set to rise: Top tips for amateur photographers | Science & Tech News
    August 18, 2024
    Scientists Want to See Videos of Your Cat for a New Study
    Scientists Want to See Videos of Your Cat for a New Study
    August 18, 2024
    OpenAI’s new voice mode let me talk with my phone, not to it
    OpenAI’s new voice mode let me talk with my phone, not to it
    August 18, 2024
  • Entertainment
  • Sports News
  • People
  • Trend
Reading: Bugs in transportation app Moovit gave hackers free rides
Share
Font ResizerAa

News Junction

  • World News
  • Business
  • Technology
  • Cryptocurrency
  • Trend
  • Entertainment
Search
  • Recent Headlines in Entertainment, World News, and Cryptocurrency – NewsJunction
  • World News
  • Business
  • Cryptocurrency
  • Technology
  • Entertainment
  • Sports News
  • People
  • Trend
Have an existing account? Sign In
Follow US
News Junction > Blog > Technology > Bugs in transportation app Moovit gave hackers free rides
Bugs in transportation app Moovit gave hackers free rides
Technology

Bugs in transportation app Moovit gave hackers free rides

Published August 14, 2023
Share
4 Min Read
SHARE

Hackers could have hijacked the user accounts of a popular transportation app and used them to get free rides and access people’s personal information, according to a security researcher.

Omer Attias, a security researcher at SafeBreach, said he found three vulnerabilities in the Moovit app, which allowed him to collect new Moovit user’s registration information from all over the world — including cell phone numbers, email addresses, home addresses, and the last four digits of credit cards. Worst of all, the bugs could have allowed him to take over other people’s accounts, and consequently their credit cards, to pay for his own rides.

This whole chain of exploits could have been performed without the target ever finding out, apart from seeing unwanted charges on their credit card. Attias called it “the perfect attack.”

“We can fully impersonate accounts, without disconnecting them. It’s crazy, we actually have the ability to perform all the operations on behalf of different accounts, including ordering train tickets,” Attias told TechCrunch in an interview ahead of his talk at the Def Con hacking conference in Las Vegas. “And additionally, we can access all of their personal information.”

To demonstrate the impact of the bugs he found, Attias created a custom interface that allowed him to take over other people’s accounts with a couple of taps. And while Attias said he tested his exploits only in Israel, he said he thinks it could have worked in other cities given that Moovit operates all over the world.

Moovit is an Israeli startup that was acquired by Intel in 2020 for $900 million. The app allows users to find routes and view public transportation systems’ maps, as well as to purchase and use tickets. The app and its underlying technology are widely used worldwide: Moovit claims to serve 1.7 billion riders in 3,500 cities across 112 countries.

While the impact of these vulnerabilities was potentially massive, Moovit said there is no evidence that malicious hackers found and exploited these bugs. Attias said that he reported all the bugs he found to the company in September 2022, and the company subsequently fixed them.

“Moovit was aware of and rectifying the issue when it was reported, and took immediate steps to finish correcting the issue,” Moovit spokesperson Sharon Kaslassi told TechCrunch. “The vulnerabilities have long since been fixed and no customer action is required. It’s important to note that no bad actors took advantage of these issues to access customer data. Additionally, no credit card information was exposed as Moovit and Moovit-Pango do not keep credit card information on file.”

Kaslassi also said that “ticketing service relevant to these findings is active in Israel only.”

“According to our records, neither Safebreach or anyone else took advantage of any customer data in or outside of Israel,” the spokesperson added.

In response to Moovit’s comments, Attias said that he and his colleagues “believe we could have charged any customer not limited to Israeli customers. We haven’t seen any differentiator between Israeli and non Israeli customers in their API requests.”

Read more from Black Hat:

#Bugs #transportation #app #Moovit #gave #hackers #free #rides

- Advertisement -
TAGGED:appBugsfreeGavehackersMoovitridesTransportation
Share This Article
Facebook Twitter Pinterest Whatsapp Whatsapp LinkedIn Email Copy Link Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article China criticises visit of ‘troublemaker’ Taiwan VP to US China criticises visit of ‘troublemaker’ Taiwan VP to US
Next Article ‘Pullback Will Be Short-Lived’: Daniel Ives Says Buy These 2 AI-Driven Tech Stocks — Including One With 260% Upside ‘Pullback Will Be Short-Lived’: Daniel Ives Says Buy These 2 AI-Driven Tech Stocks — Including One With 260% Upside
- Advertisement -

Latest Post

BTC, ETH, XRP, BNB, SOL, ADA, DOGE, PI, LEO, HBAR
BTC, ETH, XRP, BNB, SOL, ADA, DOGE, PI, LEO, HBAR
Cryptocurrency
Ousted Bangladesh PM Hasina’s party barred from election as party registration suspended
Ousted Bangladesh PM Hasina’s party barred from election as party registration suspended
World News
Altcoins’ roaring returns and falling USDT stablecoin dominance suggest ‘altseason’ is here
Altcoins’ roaring returns and falling USDT stablecoin dominance suggest ‘altseason’ is here
Cryptocurrency
Cassandra Ventura testifies, tells jury freak offs became a job
Cassandra Ventura testifies, tells jury freak offs became a job
World News
How to Use tsUSDe on TON for Passive Dollar Yield in 2025
How to Use tsUSDe on TON for Passive Dollar Yield in 2025
Cryptocurrency
White South Africans arrive in US after Trump administration granted them refugee status | World News
White South Africans arrive in US after Trump administration granted them refugee status | World News
World News
- Advertisement -

You Might Also Like

Japanese RPG Remakes : persona 2
Technology

Japanese RPG Remakes : persona 2

February 9, 2024
As unicorns grow rarer, maybe it’s time to look toward revenue, not valuations
Technology

As unicorns grow rarer, maybe it’s time to look toward revenue, not valuations

August 17, 2023
Bitcoin Price Mini-App Games : Mini-App Game
Technology

Bitcoin Price Mini-App Games : Mini-App Game

July 22, 2024
Okay, fine, I want Elon Musk and Mark Zuckerberg to fight
Technology

Okay, fine, I want Elon Musk and Mark Zuckerberg to fight

August 12, 2023

About Us

NEWS JUNCTION (NewsJunction.xyz) Your trusted destination for global news. Stay informed with our timely and accurate reporting on diverse topics, including politics, technology, science, entertainment, sports, and more. Count on us for unbiased and reliable updates at your fingertips.

Quick Link

  • About
  • Disclaimer
  • Privacy Policy
  • Terms of Use
  • Contact

Top Categories

  • World News
  • Business
  • Technology
  • Entertainment
  • Cryptocurrency
  • Sports News
  • Trend
  • People

Subscribe

Subscribe to our newsletter to get our newest articles instantly!

    © 2023 News Junction.
    • Blog
    • Advertise
    • Contact
    Welcome Back!

    Sign in to your account

    Username or Email Address
    Password

    Lost your password?