Skip to Content
News

Thousands of L.A. Based Electric Car Share Users’ Personal Information Exposed in Data Leak

Blink Mobility, the company that manages the Blue LA electric car share program in partnership with the City of Los Angeles, first learned of the data leak on December 14, according to a notice from Blink Mobility that was reportedly sent to “impacted users" on January 5.

via Blink Mobility/X

More than 22,000 Blue LA users had their phone numbers, email addresses, encrypted passwords and other personal information exposed in a data leak last year, according to a report by Cybernews.

A spokesperson for the Los Angeles Department of Transportation (LADOT) confirmed the data leak. "LADOT was informed by the contractor of this issue," Colin Sweeney told L.A. TACO.

Blink Mobility, the company that manages the Blue LA electric car share program in partnership with the City of Los Angeles, first learned of the data leak on December 14, according to a notice from Blink Mobility that was reportedly sent to “impacted users" on January 5.

“On 12/14/2023, Blink Mobility received notice that a former vendor’s database had a vulnerability that may have comprised some customer data.” The database was part of a “legacy system” that had been replaced in August of 2023, the company said.

“We believe that the vulnerability may have comprised data that includes some customer’s phone numbers, email addresses, encrypted passwords, account registration dates, device info, device tokens, and details on subscription and rented vehicles.”

Blink Mobility advised customers to update passwords “on any applications that share the same password as the legacy Blink Mobility app,” even though the data that was exposed was encrypted.

Cybernews first reported on the data leak at the end of last year, after their research team discovered the exposed database through metadata that “was then indexed by search engines.” Their investigation revealed that more than 22,000 users were contained in the database.

Cybernews reported the leak to Blink Mobility the same day they discovered it. A couple of days later, the database was gone, Cybernews reported.

It is unclear if hackers accessed the data before it was taken down.

“Personally identifiable information from car renting companies is highly valued among black-hat hackers and is often sold in batches on cybercrime marketplaces on the dark web,” according to Cybernews.

“In the wrong hands, this data can be exploited for financial gain,” Cybernews researchers said. “Threat actors could potentially use the exposed information to track users’ movements, manipulate booking, and engage in fraudulent activities.”

Twenty-two days after first learning of the data leak, on January 5, Blink Mobility sent a “notice of data breach” to impacted users, according to Colin Sweeney, Director of Public Information for LADOT.

Sweeney did not confirm how many users were impacted by the leak when asked. 

Blink Mobility’s notice informed users of what happened, what information was potentially leaked as well as steps that users should take to protect themselves.

In a request for comment, L.A. TACO asked Blink Mobility why they didn’t immediately notify customers.

“Blink Mobility is committed to providing a secure environment for our customers,” the company’s notice reads. “Our new mobile app launched in August 2023, is fully built and maintained by us. Furthermore, we are expanding our cybersecurity auditing process for partners and third-party vendors.”

Blue LA, in partnership with LADOT, began service in 2018 and was briefly managed by a French company before Blink Mobility took over in late 2020. Through an app, Blue LA users can rent electric Chevy Bolts by the minute. Today there are roughly 40 Blue LA charging stations and 100 vehicles available.

If you’ve had issues with Blue LA, please contact our investigative reporter - LexisOlivier@Gmail.com.

Stay in touch

Sign up for our free newsletter

More from L.A. TACO

Protester Whose Testicle Exploded After LAPD Officer Shot Him with ‘Less Lethal’ Firearm Receives $1.5 Million Settlement

Benjamin Montemayor had been protesting on Hollywood Boulevard for several hours on June 2, 2020, when at least 50 police officers descended upon his group and began firing munitions at the crowd, according to his civil rights lawsuit filed in Los Angeles federal court.

May 17, 2024

Westlake’s Oldest Gay Bar Set to be Demolished

Opened in the early 1960s, the Silver Platter has long been known as a safe space for immigrant gay and transgender communities in Westlake. The building dates back to the 1920s.

May 17, 2024

What To Eat This Weekend Around L.A.: Salvadoran Fried Chicken Sandwiches, 48-Hour Pho, and Tacos Placeros

Plus, a new Enrique Olvera-approved monthly "mercadito" in D.T.L.A., a new arepa spot with patacon burgers that use fried plaintains for buns, and more in this week's roundup.

May 17, 2024

The 13 Best Tacos In Boyle Heights

Boyle Heights is arguably the city’s most important local taco galaxy in the larger taco universe that is Los Angeles. Remember, this is Boyle Heights! It's not East L.A., and it is most definitely not just some vague place known as “the Eastside.”

May 16, 2024

Here Are All the Restaurants (and the One Taquería In the Entire Country That Got a Star) On Michelin’s First Ever Mexico Guide

Europe's Michelin Guide recognized both Baja Californias, Quintana Roo, Mexico City, Oaxaca, and Nuevo Léon. Most of the usual nice restaurants got stars, but there were some questionable omissions. Also, in a country teeming with life-changing street food, only one taquería in the entire country was awarded "1 star."

May 15, 2024
See all posts