According to media reports in the computer magazine c't and the weekly newspaper Zeit, there was a serious data leak at the car rental company Buchbinder as early as January 2020. As a result, personal data of three million customers leaked unencrypted onto the internet, where it was freely accessible to any internet user. Apparently, all Buchbinder customers (car renters and drivers) from 2003 to 2020 are affected.
Configuration error led to data breakdown
The data leak was apparently triggered by a configuration error on one of Buchbinder's backup servers, resulting in the following personal data of the affected customers being leaked onto the internet:
- Name
- Address
- Date of birth
- Mobile phone number
- E-mail address
- Driving licence number
- Driving licence issue date
- Payment information and bank details
Data breach victims become victims of phishing attempts
Since the disclosed data was publicly available on the internet, basically every internet user could access and download all data unencrypted. It is therefore very likely that there will be more phishing attempts, blackmail and other fraudulent methods. Identity theft cannot be ruled out either.
Claims for damages due to data protection violations
The disclosure of personal data is likely to constitute a serious breach of the DSGVO (European Data Protection Regulation). According to Art 82 DSGVO, any person who has suffered material or immaterial damage due to a data protection violation is entitled to claim damages against the responsible party, thereby against Buchbinder.