Zoomcar, the Indian peer-to-peer car-sharing platform, has disclosed a data breach that exposed sensitive customer information of 8.4 million people.
According to a filing with the US Securities and Exchange Commission (SEC), Zoomcar Holdings, Inc. detected unauthorized access to its internal systems after employees received messages from a threat actor. The company launched an investigation, confirming that non-financial personal information of over 8 million users had been compromised, including:
The type of attack, or if the stolen data has been leaked, remains undisclosed for now.
This isn’t the first time Zoomcar has been hit. In 2018, a major breach impacted 3.5 million customers, exposing hashed passwords and contact information. That dataset surfaced on underground marketplaces two years later, placing affected users at increased risk of phishing, identity theft, and fraud.
The latest breach, while not believed to include financial data, still provides valuable information for threat actors looking to build detailed user profiles or carry out targeted attacks.
Even though Zoomcar claims no financial or password data was exposed, the combination of names, addresses, car registration numbers, and phone numbers can be exploited in:
Zoomcar has said it is still assessing the scope of the breach and has not responded to media inquiries about the nature of the incident.
If you’ve ever used Zoomcar, it’s a good idea to take precautions — even if financial data wasn’t exposed:
Bitdefender Digital Identity Protection helps you monitor data leaks and alerts you if your personal details appear on the Dark Web — empowering you to act fast.
tags
Alina is a history buff passionate about cybersecurity and anything sci-fi, advocating Bitdefender technologies and solutions. She spends most of her time between her two feline friends and traveling.
View all postsMay 23, 2025
May 16, 2025
April 03, 2025
March 12, 2025