As it turned out, the data leak originated from private institutions that certify imported used cars in Ukraine. They uploaded scanned documents in large volumes to a cloud service they considered reliable, but in reality, the storage was not even protected by a simple password.
Back in April 2022, Irish cybersecurity expert Jake Dixon stumbled upon the issue—he accidentally found this storage using specialized software. The specialist immediately informed the Ukrainian authorities, but no reaction followed. The database could be used without hindrance until April 1, 2025, when a journalist from the Kyiv Independent raised the issue again—only then was access finally blocked.
"If this data hasn't already fallen into the hands of malicious actors, it's only a matter of time. And I know for a fact that certain Russian intelligence units are hunting precisely for such vulnerabilities," Dixon emphasized.
What is most alarming is that no state body has acknowledged its responsibility. Neither CERT-UA, nor the Ministry of Digital Transformation, nor the Ministry of Regional Development have provided official comments on the incident or explained why the leak warning was ignored for almost three years.








