More than 22,000 Blue LA users had their phone numbers, email addresses, encrypted passwords and other personal information exposed in a data leak last year, according to a report by Cybernews.
A spokesperson for the Los Angeles Department of Transportation (LADOT) confirmed the data leak. "LADOT was informed by the contractor of this issue," Colin Sweeney told L.A. TACO.
Blink Mobility, the company that manages the Blue LA electric car share program in partnership with the City of Los Angeles, first learned of the data leak on December 14, according to a notice from Blink Mobility that was reportedly sent to “impacted users" on January 5.
“On 12/14/2023, Blink Mobility received notice that a former vendor’s database had a vulnerability that may have comprised some customer data.” The database was part of a “legacy system” that had been replaced in August of 2023, the company said.
“We believe that the vulnerability may have comprised data that includes some customer’s phone numbers, email addresses, encrypted passwords, account registration dates, device info, device tokens, and details on subscription and rented vehicles.”
