An Open Production Database Blown Wide Open

A hacker claims to have extracted the production database from Cars Software, a Norwegian company that provides management software used by over 500 garages, dealers, and automotive wholesalers in Norway. According to their post published on August 7, 2026, the database was configured for public read access: no authentication, no tokens, no referer checks were required to view the information. Reading access was still available, according to the author, on August 6, 2026.

The automated tool used for this detection has been dubbed “CredHarvest V6” by its creator, who presents the operation as a discovery of inadequately protected databases. No write tests were reportedly conducted.

The Exposure Numbers

The claimed dataset includes 315,435 records related to Cars Software's activities. Here’s the breakdown provided by the hacker:

Category Number of Records
Distinct names (individuals and businesses) 166,524
Unique phone numbers 148,288
License plates 73,581
Customer numbers 40,551
Consent records (category 1) 112,639
Consent records (category 2) 119,744
European vehicle control notifications 80,789
Estimates 1,761
Information records 502
Mechanical intervention files 48
Identifiable automotive centers 289

In total, 148,288 motorists are reportedly affected by the exposure of their phone numbers, accompanied by data much richer than just a simple directory.

Named Corporate Fleets

The publication also identifies several fleet operators whose data could appear in the extract, including:

  • Oslo Taxibuss AS
  • Fredrikstad Kommune
  • Bergen Bilutleie AS
  • Norsk Bilpool AS

For these organizations, the alleged exposure could reveal the relationship between certain vehicles and their automotive providers — potentially sensitive information from an operational standpoint.

The Cocktail That Turns a Leak into a Phishing Weapon

The stakes go beyond the simple disclosure of a directory. The claimed data links several categories of information: a name can be associated with a phone number, a license plate, and a service center. This combination radically changes the nature of the risk.

An isolated file of phone numbers already holds value for fraudsters. But when enriched with a license plate and the name of a garage, the social engineering scenario becomes significantly more precise. An attacker can pose as a known garage to the victim and mention an inspection, a recall, or an intervention regarding their actual vehicle — significantly reducing the warning signals typically associated with generic phishing.

The 80,789 vehicle control notifications mentioned in the publication constitute a particularly sensitive example. They link license plates to recalls intended for vehicle owners. An attacker can exploit this context to construct a message that appears perfectly legitimate.

The 1,761 estimates recorded add an additional layer of credibility. According to the hacker, 1,200 would be pending and 561 would have been accepted, with amounts ranging from zero to 601,000 Norwegian kroner (average of 7,635 NOK). A malicious message can leverage the supposed existence of a real automotive operation to prompt the victim to click or share information.

Data Age That Temper Risks — Without Nullifying Them

The author claims that the data primarily dates back to 2016 and 2017. This age potentially limits their operational value: phone numbers may have changed, vehicles may have been resold, business relationships may have evolved. However, the hacker asserts that some contact details, registrations, and business ties may still be valid. This claim remains the hacker's and has not been independently verified.

The Norwegian and European Framework

In Norway, the Data Protection Authority (Datatilsynet) has a role equivalent to that of the CNIL in France. The General Data Protection Regulation (GDPR), applicable in the European Economic Area, requires data controllers to notify the supervisory authority of any personal data breach within 72 hours of becoming aware of it, and then to inform affected individuals when the breach poses a high risk to their rights and freedoms.

At the time of writing this article, the Datatilsynet website mentioned a recent avvnsmelding (incident notification) from the company Ryde (scooter rental), confirming the ongoing notification activity in Norway. However, no public mention of Cars Software had yet been published by the Norwegian authority.

The CNIL, for its part, defines a data breach as “the destruction, loss, alteration, unauthorized disclosure of personal data, or unauthorized access to such data, whether accidental or unlawful.” A production database accessible without authentication clearly falls into this framework.

A Pattern That Is Not Isolated

The ZATAZ article recalls that a leak of this type had already impacted France in 2025 and 2026, illustrating a broader trend. The same site also reports, on the same date, a presumed Firebase leak exposing Pokémon kiosks (206,092 email addresses, 70,546 credit card fingerprints), again via a database configured for public reading without authentication.

This modus operandi — a production database left open, detected by automated tools — is not new but continues to be effective. Massive infrastructure scanning tools like CredHarvest V6 allow malicious actors to map exposed databases on a large scale without requiring particular expertise in intrusion.

Moreover, the pseudonymous Cybernox, active since March 2026, recently claimed the leak of 3 million Bloctel numbers (the French opposition service to telemarketing), demonstrating the particular allure of data related to phones and consents for malicious actors.

Key Takeaways

  • 148,288 Norwegian motorists are potentially affected, with data going well beyond just a phone number.
  • The combination of name + phone + plate + garage constitutes prime material for targeted and credible phishing campaigns.
  • The data primarily dates back to 2016-2017, which reduces but does not eliminate the risk.
  • No official notification from the Datatilsynet had been made public at the time of writing.
  • Affected Norwegian motorists should remain vigilant regarding any messages mentioning vehicle inspections, manufacturer recalls, or automotive estimates, even if they seem to come from a known garage.

This case serves as a reminder of a truth often overlooked: a production database must never be accessible without authentication. The combination of contextual data — here, the automotive realm — transforms a technical leak into an operational threat for hundreds of thousands of people.