How the Elifelimo Data Breach Exposed 2,450 Travelers’ Personal Info
How does a niche airport transfer service end up with its customers' personal data circulating on underground forums? In the case of Elifelimo, the answer traces back to October 23, 2024, when records from the company's booking database surfaced in dark web monitoring channels. The exposed data covered 2,450 individuals whose names, email addresses, and phone numbers were included in the leak -- the kind of contact information that feeds directly into targeted phishing and social engineering attacks.
Why This Is Dangerous
Travel service databases are a high-value target precisely because they combine personal identity data with behavioral information. Knowing someone's name, phone number, and email is enough to craft convincing impersonation messages. When that data comes from a service associated with specific travel activity, it adds authenticity that generic phishing lures cannot match. Attackers who obtain this data can contact victims posing as the airline, the hotel, or the car service itself.
What Was Exposed
- Email addresses -- contact identifiers usable for phishing, spam, and account recovery attacks
- Phone numbers -- enabling SMS phishing (smishing) and voice-based social engineering
- First and last names -- real identity data that makes fraudulent contact messages convincing
Why This Matters
Even without passwords in this dataset, the combination of name, email, and phone number is a well-known precursor to account takeover through social engineering. Attackers use this data to impersonate victims when contacting customer support lines, bypassing knowledge-based authentication. The same data feeds identity theft schemes, enabling fraudulent account creation in the victim's name. Phone numbers specifically open the door to SIM-swapping attacks, where criminals convince mobile carriers to transfer a victim's number to a new SIM -- bypassing SMS-based two-factor authentication on banking and email accounts.
How the Elifelimo Database Breach Happened
Elifelimo operates as an airport-to-hotel vehicle hiring service, meaning its core product is booking management -- a function that requires storing customer contact details. Database breaches at this type of business typically result from one of several vectors: an exposed or misconfigured database accessible without authentication, a vulnerability in the booking platform's web application layer, or compromised administrative credentials. The structured, tabular format of the leaked data is consistent with a direct database exfiltration rather than a scraping or phishing campaign targeting customers. Once obtained, the data was distributed through underground channels where it was observed by dark web monitoring systems.
Check If You Are Affected
HEROIC monitors over 400 billion breached records across dark web forums, private channels, and data dumps -- including travel and hospitality sector breaches like this one from Elifelimo. Search your email address now to find out if your information appeared in this breach or any other known exposure.
Breach Breakdown
2,450 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds