Kars4Kids is a charity that asks people to donate their cars, motorcycles, RVs, and real estate. They are most known for their nationwide advertising using their hypnotic theme song where a child and a Johnny Cash impersonator sing the phone number and invites people to donate their cars today.
On the 3rd of November, Bob Diachenko, Director of Cyber Risk Research at Hacken, found what appeared to be a publicly accessible MongoDB. Upon further investigation, the data seemed to contain the emails and personal data of 21,612 Kars4Kids donors/customers and super administrator login and password details.

What is worse is that there were internal accounts with usernames and passwords that cybercriminals may have used to access the Kars4Kids dashboard, that would give them access to even more sensitive data—like vacation vouchers (free holidays for those that donated their vehicles) and receipts, with such personal data like emails, home addresses, phone numbers, and etc.


As security researchers never circumvent passwords or access this type of data, we can only speculate that cybercriminals could easily log in to accounts or abuse admin privileges.
The Ransom Note
We have seen multiple misconfigured instances of MongoDB where human error makes the database publicly accessible without a password. This means that anyone with an internet connection could have had access to Kars4Kids' data. In fact, there is clear evidence that cybercriminals placed a ransom note inside their database.

In 2017, three groups of hackers wiped around 26,000 MongoDB databases and demanded victims pay about $650 per database on average to have it restored. In total, researchers estimate as many as 75,000 databases were affected. This March, Bob Diachenko conducted a test by creating a honeypot database that contained 30GB of fake data. It took only three hours for hackers to identify the database before wiping out its data in just 13 seconds and leaving a ransom note demanding 0.2 Bitcoin.
We cannot confirm or deny that cybercriminals have downloaded the entire Kars4Kids database, but the ransom note provides reasonable suspicion that it is a possibility. It is unclear how long the data was exposed or how many others gained access to it before the notification was sent and it was ultimately secured.
The Firewall at the Top and Response
On the 3rd of November, a notification email was sent to multiple email addresses with no reply, and the database remained open until the evening of November 5th. It took 3 hours by phone to reach someone, despite telling the volunteers who answer the phones that this is a serious issue and we need to speak with someone in the IT Technology department or senior management. On one occasion the call was forwarded to someone in Israel who could not give names, contacts, or emails of anyone who could secure the data, and instead suggested calling the same main number again.
We understand that it is a common practice to create a buffer zone between the public and senior managers or leadership. However, the most shocking thing was that an organization or company would not have a data breach or crisis action plan for when a report is made. During the notification process, we told anyone who would listen what happened, how important it is, and that we must speak with someone to help secure this data urgently. The issue here is that every organization must understand the value of the information they store and collect. They must take every possible step to secure and protect that data. This includes training everyone to be on the same page and enacting a data breach protocol for when the worst happens.
Kars4Kids' Official Response
On November 7th, we received the following reply from a Kars4Kids representative:
We take the security of our donors' information extremely seriously. After looking into this matter, we immediately secured the vulnerable database, notified the FBI cyber division, and also informed those donors whose information was affected. Unfortunately, as a nonprofit organization, we do not have a discovery bounty program in place. We do very much appreciate your letting us know of this issue and your dedication to keeping the web secure.
That gap is exactly what a managed bug bounty program closes: instead of relying on an outside researcher to track down the right contact by phone, a bug bounty platform gives security researchers a clear, pre-approved channel to report issues like this one before they turn into a public breach.
Controversy
As security researchers, our primary goal is protecting users' data online and data security education. We report facts and opinions and have no bias toward the companies or individuals we report on. Charity is a very honorable cause, and we are not implying any wrongdoing by Kars4Kids or their sister company Oorah. However, when researching more closely, we discovered that the charity has faced some controversy in the past, and we wanted to include that in the report.
The subject of the controversy is the Kars4Kids advertising jingle. The song was recorded in 1999 and has achieved cult status for good or bad. It has been parodied by FOX's cartoon series Family Guy, used as CIA torture in an SNL skit, and radio host Don Imus was recorded on a "hot mic" telling the charity to "go to hell" over the song.
Questions Remain
Suffering a data breach can happen to anyone, and Kars4Kids is not unique in this case. Companies and charities large and small must make sure that they are taking every possible step to secure the data they collect or store. Digging deeper into the publicly accessible database made the pieces of the puzzle start to become clearer on what Kars4Kids actually does and how it looks from the inside.
The incident was also independently reported by outlets including TechCrunch and SC Media.
Is Kars4Kids (Kars for Kids) Legit? What This Breach Means for Donors
Kars4Kids—widely known for its "K-A-R-S for Kids" jingle—is a registered nonprofit, and this incident alone isn't evidence that the charity acted in bad faith. What it does show is a real security lapse: donor emails, home addresses, phone numbers, and internal admin credentials sat in a database with no password, open to anyone who found it. On the security-response side, Kars4Kids acted reasonably once notified—the database was secured, the FBI's cyber division was informed, and affected donors were told. If you're weighing whether Kars4Kids (sometimes searched as "Kars for Kids") is trustworthy before donating a car or other property, a data breach and a charity's overall financial legitimacy are related but separate questions—this report only speaks to the former. Kars4Kids publishes its own programs, team, and financial disclosures if you want to evaluate that side directly.
How to Protect Your Data When Donating to a Charity
If you're donating a vehicle, cash, or personal information to any charity—Kars4Kids included—a few basic checks lower your risk:
- Verify the charity's registration and financial disclosures through the IRS Tax Exempt Organization Search or a rating service like CharityWatch before donating.
- Share only the information a donation actually requires; a vehicle pickup rarely needs more than a name, phone number, and pickup address.
- Ask what happens to your data after the donation, and whether it's shared with sister organizations or partners.
- If a charity you've donated to discloses a breach, check which specific data types were exposed before assuming the worst.
- Use a dedicated email address for donations and sign-ups, so a leaked address is easy to identify and filter later.
- If you believe your personal data was misused after a breach, you can file a report with the FBI's Internet Crime Complaint Center (IC3).
Kars4Kids Data Breach: FAQ
Is Kars4Kids (Kars for Kids) legit?
Kars4Kids is a registered nonprofit that has operated for decades. This data breach is a security incident, not evidence of fraud, but it's a reasonable prompt to review a charity's data practices, not only its mission, before donating.
What data was exposed in the Kars4Kids breach?
An unsecured MongoDB database exposed personal information for 21,612 donors, including emails, home addresses, and phone numbers, along with internal administrator login credentials and records such as vacation vouchers and receipts.
Did Kars4Kids notify affected donors?
Yes. According to Kars4Kids' statement to HackenProof, the organization secured the database, notified the FBI's cyber division, and informed the donors whose information was affected.
Is donor data still at risk?
The exposed database was secured on November 5, 2018, days after discovery. A ransom note found inside the database suggests unauthorized parties may have accessed it before it was secured, though the full extent of any additional access couldn't be confirmed.



