E-commerce portal vulnerabilities exposed AWS credentials, customer records, and internal reports — now patched, but transparency remains in question
Serious Security Flaws Found in Tata Motors’ E-Dukaan Platform
Indian automotive giant Tata Motors has confirmed it fixed a series of security vulnerabilities in its systems that exposed sensitive customer and internal data. The flaws were discovered by security researcher Eaton Zveare in the company’s E-Dukaan e-commerce portal, used to sell commercial vehicle spare parts.
Zveare uncovered critical oversights in the portal’s source code, which included private AWS keys — effectively exposing Tata’s cloud infrastructure.
What Was Exposed: From Personal Info to Internal Reports
According to Zveare, the compromised AWS credentials could grant access to a wide range of sensitive data, including:
- Hundreds of thousands of customer invoices with names, addresses, and PAN (Permanent Account Numbers)
- MySQL database backups and Apache Parquet files containing private customer communications
- Over 70 terabytes of data tied to Tata’s FleetEdge fleet-tracking software
- Admin access to a Tableau dashboard showing internal financial and performance reports, plus dealer scorecards
- API credentials for Tata’s Azuga fleet management platform, used for test drive bookings
Zveare highlighted that this level of access would have allowed a malicious actor to view, modify, or delete extensive company and user data.
Ethical Disclosure and Limited Transparency
Zveare responsibly reported the vulnerabilities to CERT-In (India’s Computer Emergency Response Team) in August 2023. Tata Motors acknowledged the issues in October 2023, stating that initial loopholes were secured and work on the AWS-related risks was ongoing.
Tata Motors has since confirmed that all vulnerabilities were fully addressed in 2023, but notably:
- The company did not clarify when each issue was resolved.
- It has not confirmed whether affected customers were notified of the data exposure.
This lack of transparency raises concerns about how companies communicate with users when their data is at risk — particularly in large, high-trust brands like Tata Motors.
Tata Motors’ Response: Fixes Made, Monitoring in Place
In a statement to TechCrunch, Sudeep Bhalla, Head of Communications at Tata Motors, assured:
“The reported flaws and vulnerabilities were thoroughly reviewed… and were promptly and fully addressed.”
He added that the company:
- Performs regular security audits by top cybersecurity firms
- Maintains detailed access logs to detect unauthorized activity
- Collaborates with security researchers to continually improve its defenses
While these are best practices in modern cybersecurity, the incident underscores the risks of embedded secrets in source code and the importance of regular code reviews and security scanning.
Lessons for the Industry: Cloud Access Risks and Proactive Disclosure
This case highlights broader industry lessons:
- Hardcoding credentials in web apps is a serious oversight, especially at scale.
- Cloud platforms like AWS offer powerful tools, but they’re only as secure as the access controls around them.
- Ethical hackers and researchers play a vital role in improving digital safety — rewarding and listening to them is key.
- Proactive customer disclosure when sensitive data may be compromised is crucial for building trust.








