Carla accidentally left 48,000 car rental confirmation files publicly accessible. Here’s what was leaked, how scammers may use travel details, and how you can protect yourself before your next trip.
Table of Contents
What Happened?
Researchers found the files on June 3, 2026, in an unsecured Amazon Web Services storage bucket. An AWS bucket is an online space companies use to store files.
Most documents were car rental confirmations containing personal and travel details. Cybernews contacted Carla, and public access was closed by June 29.
Researchers found no evidence that criminals used the information. However, leaked travel details can help scammers create convincing emails about canceled bookings or unexpected payments.
Many people do not know when their information appears in a data leak. Automatic monitoring can help you notice problems before suspicious messages or account activity appear.
Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.
Who Was Affected and What Data Was Leaked?
Carla operates across 180 countries and says it serves around two million users each year.
However, Carla has not publicly said how many individual customers were affected. Cybernews found about 48,000 documents, but some customers may have had multiple files.
The leaked information included:
- Full names
- Email addresses
- Phone numbers
- Booking and voucher numbers
- Rental dates and costs
- Pickup and drop-off locations
- Vehicle details, including size, model, and transmission type
Carla has not said that passwords, payment card numbers, passport details, or home addresses were included.
Even without passwords or card numbers, these details can make fake messages look convincing.
A scammer could mention your booking number, rental dates, or pickup location while requesting payment.
How Carla’s Rental Files Became Publicly Accessible
Cybernews says the files were stored in an AWS bucket without proper access controls.
Access controls are settings that decide who can view or download stored files.
Without the correct restrictions, people or automated scanning tools may have been able to find and open the documents.
The source does not explain why the storage settings allowed public access.
There is also no evidence that hackers broke into Carla’s systems.
This appears to have been a data leak, meaning information was accidentally left accessible rather than stolen through a break-in.

At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
