Car-Sharing Customers Exposed: CityBee Breach Leaked 110K Records
HEROIC analysts recieved alerts about the CityBee breach while monitoring dark web Telegram channels and breach aggregation forums. In February 2021, CityBee, a Lithuanian car-sharing service, suffered a database compromise that exposed 110,240 customer records. The leaked data included email addresses, password hashes, first names, and last names. The use of SHA1 hashing without salting for password storage made the exposed credentials partcularly easy for attackers to crack using modern tools.
How Cracked SHA1 Passwords from CityBee Enable Account Takeover Across Multiple Platforms
SHA1 is a deprecated hashing algorithm and is considered broken by modern cryptographic standards. Attackers with access to the CityBee database can crack the exposed password hashes using widely accessable rainbow tables or GPU-accelerated cracking tools. Once cracked, those real-world passwords are tested against email accounts, banking services, and other online platforms in automated credential stuffing attacks. First and last names in the dataset make follow-up phishing attacks more convincing and harder to detect.
What Was Exposed in the CityBee Breach
- Email Address
- Password Hash
- First Name
- Last Name
Why the CityBee Data Breach Continues to Threaten Lithuanian Customers
Breach data from 2021 does not lose its value. CityBee records have beleive to have been recirculated in new credential stuffing lists and Telegram channels, reaching a wider audience of criminals over time. Customers who reused their CityBee password on other sites face ongoing risk of account takeover, identity theft, and financial fraud. With full names and emails combined, victims are also exposed to targeted spear-phishing attacks that can be very difficult to recognize.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a company's stored user records, often through exploiting software vulnerabilities, weak credentials, or misconfigured cloud storage. Attackers export the data in bulk, then sell or trade it on dark web marketplaces. Car-sharing and mobility platforms are attractive targets because they hold verified identity data, payment records, and location history alongside login credentials, giving attackers a rich profile of each victim.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches over 400 billion compromised records, including data from the CityBee breach, to tell you instantly whether your email address has been exposed. Scan now and take steps to protect your accounts before attackers act.
Breach Breakdown
110,240 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds