# Hacking India's largest automaker: Tata Motors

DevFeed: [Hacking India's largest automaker: Tata Motors](<https://devfeed.tech/articles/hacking-india-s-largest-automaker-tata-motors-32616.md>)

Original publisher: [Read original article](<https://eaton-works.com/2025/10/28/tata-motors-hack/>)

Author: Eaton

Published: 2025-10-29T01:05:40Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Hacking](<https://devfeed.tech/topics/hacking.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [data](<https://devfeed.tech/topics/data.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>)

Tags: [amazon](<https://devfeed.tech/tags/amazon.md>), [aws](<https://devfeed.tech/tags/aws.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [database](<https://devfeed.tech/tags/database.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [india](<https://devfeed.tech/tags/india.md>), [s3](<https://devfeed.tech/tags/s3.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

The article describes four security findings involving Tata Motors discovered in 2023. It reports that exposed AWS keys on public-facing websites enabled access to sensitive information across many S3 buckets, that weakly encrypted keys could be decrypted, that a Tableau backdoor allowed passwordless login as users including an administrator, and that an exposed Azuga API key compromised a test-drive fleet management system. The author states that the disclosed credentials were rotated and that testing did not download substantial amounts of data or show obvious evidence of malicious access.

## Source excerpt

Tata Motors gave away the keys to their infrastructure and customer data on their public websites.