El Kri!
5.5K posts





🇪🇨 🚨 Ecuador Transportation App Breach – SQLi + Full Database Exposed A dark web post claims a complete compromise of the “Tu Taxi Amigo” transportation app in Ecuador, including SQL injection access and full database exposure. 📊 Key Claims: • ~25,000 records in database • Data includes both customers and drivers: Names, emails, usernames Passwords (likely hashed, but unclear) Addresses Credit card / payment data (high risk claim) Admin panel allegedly exposed Credentials shared in clear text Attack vector explicitly stated: SQL Injection (SQLi) 🧠 Threat Intelligence Insight: • This is a critical security failure pattern: SQLi → full database extraction Hardcoded / weak admin credentials If credit card data is real: Immediate financial fraud risk Even without cards: Credential reuse attacks likely (users reuse passwords) Exposure of admin panel + creds suggests: No proper access controls / no MFA ⚠️ Assessment: • Highly plausible compromise scenario: SQLi + exposed admin creds is a common real-world chain However: Credit card claim needs verification (often exaggerated) ⚠️ Risk Implications: • Account takeover across platforms (password reuse) • Financial fraud (if payment data valid) • Targeting of drivers and customers • Full platform compromise and service abuse 📊 Status: Unverified — but technically credible and high-risk scenario ⸻ 💬 SQL injection is decades old — yet still breaking modern apps. #CyberSecurity #DataBreach #SQLi #FinTech #Ecuador #ThreatIntel #DDW




Mathias y yo en la playa. 🏝️🌸❣️





















