Startups

India shipping logistics giant Shipyaari exposed customer data

Comment

container ship
Image Credits: PixaBay / Pexels

Shipyaari, a Mumbai-based software company that offers shipping logistics to major consumer brands, exposed the personal data of thousands of its customers because of a months-long spill of its internal shipment information.

The exposed data, discovered by security researcher Ashutosh Barot, included Shipyaari customers’ names, addresses, phone numbers, order invoice amounts and delivery status. According to Barot, Shipyaari’s client tracking page was not password protected and could be viewed by anyone who had the web address.

“The exposed information could later be used to perform targeted social engineering attacks and financial frauds,” Barot told TechCrunch.

The researcher initially contacted Shipyaari about the exposure in October 2021 and the company promised a fix in December. Some changes were made, but did not fix the exposure. It was eventually fixed in late July after TechCrunch reached out about the security incident.

“I appreciate Shipyaari for fixing the issue and implementing recommendations,” Barot said.

Shipyaari fixed the exposure by removing customers’ personally identifiable information (PII) from the tracking page and restricted its access with a one-time PIN (OTP) system. It later updated the system to limit bad actors from launching automated attacks.

“Data privacy is of utmost importance to us, and we will ensure such instances should not occur in the future,” Vishal Totla, founder of Shipyaari, said in an email response to TechCrunch.

Totla said customer PII data will no longer display on the page while loading.

Shipyaari claims to handle more than 5,000 shipments a day. The company also has more than 6,000 active sellers across the country.

Barot underlined that India needed strong data privacy laws to help limit growing instances of data exposures and leaks.

Earlier this month, the Indian government withdrew the long-anticipated Personal Data Protection Bill that was promoted to bring stringent rules to help protect its citizens’ privacy. The legislation alarmed tech giants and raised concerns about how they could manage sensitive user information.

More TechCrunch

If you spend time on X or Threads, where snarky memes rise and fall, you’ve probably seen posts referencing “founder mode” over the last few days, like this: https://www.threads.net/@carnage4life/post/C_eaQAxyIcV Or…

Those ‘Founder mode’ memes keep coming

Andreessen Horowitz (a16z) has closed a satellite office in Miami Beach just two years into a five-year lease it signed for an 8,300-square-foot space. The reason? Disuse, reports Bloomberg. Miami…

Andreessen Horowitz shutters its Miami office after two years

These final maneuvers will bring to a close a troubled first crewed mission for the Boeing-made Starliner.

Boeing and NASA prepare to bring Starliner home without its crew on Friday

As Meta tries to rekindle the flame between Facebook and socially anxious youths, the company released a blog post Wednesday titled, “Navigating your 20s with Facebook.”

Facebook says, ‘How do you do, fellow kids?’

Cowboy has closed funding of around $5.5 million. With this recent funding round, Cowboy is now valued at €40 million on a pre-money basis.

E-bike maker Cowboy raises a small funding round as it targets profitability next year

HR and payroll software company Paylocity has agreed to acquire corporate spend startup Airbase for $325 million, the companies announced Wednesday. The deal is subject to regulatory approval and is…

Paylocity is acquiring corporate spend startup Airbase for $325M

A long-running lawsuit over the Internet Archive’s “emergency” e-book lending practices during the COVID-19 pandemic has ended in a loss for the website and a victory for publishers. The lawsuit…

Publishers prevail in lawsuit over Internet Archive’s ’emergency’ e-book lending

Ryan Breslow’s plan to get himself reinstalled as CEO of fintech company Bolt — and push through a $450 million fundraising deal that would value the startup at a staggering $14 billion…

Ryan Breslow’s $450M Bolt deal said to involve a restraining order now

Maybe a lack of AI characters is what Quibi got wrong. At least, that’s what one startup appears to believe.  My Drama is a new short series app with more…

Short series app My Drama takes on Character.AI with its new AI companions

A 23-year-old woman who allegedly killed two men in March while using Ford’s hands-free system, BlueCruise, has been charged with DUI homicide by Pennsylvania State Police. The woman, Dimple Patel,…

Woman who allegedly killed two people using Ford BlueCruise charged with DUI homicide

The hiring effort comes after X, formerly known as Twitter, laid off 80% of its trust and safety staff since Musk’s takeover.

X is hiring staff for security and safety after two years of layoffs

Hiya, folks, welcome to TechCrunch’s regular AI newsletter. If you want this in your inbox every Wednesday, sign up here. This week in AI, two startups developing tools to generate and…

This Week in AI: VCs (and devs) are enthusiastic about AI coding tools

The Cosmos Institute, a nonprofit whose founding fellows include Anthropic co-founder Jack Clark and former Defense Department technologist Brendan McCord, has announced a venture program and research initiatives to —…

The Cosmos Institute, whose founding fellows include Anthropic co-founder Jack Clark, launches grant programs and an AI lab

Once linked, parents will be alerted to their teen’s channel activity, including the number of uploads, subscriptions and comments.

YouTube debuts new parental controls aimed at teens

No one is putting the remote working genie back in the bottle. Which is good news for Oyster, a payroll and HR platform that specializes in distributed workforces — or…

As remote working keeps rolling, Oyster raises $59M Series D at $1.2B valuation

For the college students who are satisfied with dating apps, which may not be many, Tinder announced Wednesday a series of updates to Tinder U, its in-app feature that caters…

Tinder update targets college students as dating apps struggle

The exact contents of X’s (now permanent) undertaking with the DPC have not been made public, but it’s assumed the agreement limits how it can use people’s data.

Ireland’s privacy watchdog ends legal fight with X over data use for AI after it agrees to permanent limits

Years ago, Twitter tried but eventually walked away from building TV apps after getting a lukewarm reception. Now, as it looks to revive its advertising business, its new incarnation X…

X doubles down on video with a new TV app

Apple is likely to unveil its iPhone 16 series of phones and maybe even some Apple Watches at its Glowtime event on September 9.

Apple event 2024: How to watch the iPhone 16 launch

Korea’s Institute of Machinery and Materials this week showcased a robotic wheelchair with large, deformable wheels that can manage rocks, stairs and other obstacles. During normal operation, the wheel maintains…

Watch this robotic wheelchair’s compliant wheels take on bumps, rocks and stairs

Mayfield is launching AI Garage, a $100 million initiative for ideation-stage founders interested in building “AI teammate” companies.

Mayfield allocates $100M to AI incubator modeled after its entrepreneur-in-residence program

Anthropic is launching a new subscription plan for its AI chatbot, Claude, catered toward enterprise customers that want more administrative controls and increased security. Claude Enterprise will compete with OpenAI’s…

Anthropic launches Claude Enterprise plan to compete with OpenAI

Time is running out to take advantage of our Student Pass discount for TechCrunch Disrupt 2024. Students and recent graduates can still save up to $200 until September 6 at…

Students and recent grads: Only 3 days left to save on TechCrunch Disrupt 2024 Student Passes

Fast-forward to today, Slauson & Co. remains even more committed to the mission of inclusivity in its funding, and it seems limited partners have its back. 

Slauson & Co. raises $100M Fund II proving appetite for inclusion persists

Safe Superintelligence (SSI), the AI startup co-founded by former OpenAI chief scientist Ilya Sutskever, has raised over $1 billion in capital from investors including NFDG (an investment partnership run by…

Ilya Sutskever’s startup, Safe Superintelligence, raises $1B

The American sports betting market produced $10.9 billion in revenue in 2023 for casinos, sportsbooks and iGaming, according to the American Gambling Association. One of the reasons this industry is…

DubClub wants amateur sports bettors to win more

New climate tech VC firms have emerged in recent years, but existing ones are also raising larger funds. Founded in 2007, Dutch firm SET Ventures is one of the latter.…

Dutch clean energy investor SET Ventures lands new €200 million fund, which will go toward digital tech

Revefi connects to a company’s data stores and databases (e.g. Snowflake, Databricks and so on) and attempts to automatically detect and troubleshoot data-related issues.

Revefi seeks to automate companies’ data operations

If you build an AI search product, you compete with Google. But Google has a lot easier time answering queries with a single, simple answer, such as “how many is…

With $50M in new funding, You.com thinks its AI can beat Google on hard questions

Featured Article

reMarkable’s Paper Pro adds color, light and more but keeps the focus on ‘focus’

The $499 Paper Pro — a new naming convention to indicate it is a higher-end alternative to the now-$379 reMarkable 2, not a direct successor — is momentous for its addition of both color and a “frontlight,” though both features are what you might call muted.

reMarkable’s Paper Pro adds color, light and more but keeps the focus on ‘focus’