If You Use Kavim, This 28,783-Record Breach Should Concern You
HEROIC analysts identified a database breach affecting Kavim, an Israeli public transportation company, on August 15, 2024. The incident exposed 28,783 records belonging to users of the kavim-t.com platform. The compromised data included email addresses, phone numbers, first names, and last names — no passwords were involved in this breach.
Even without passwords, this combination of contact and identity data puts affected individuals at direct risk. Attackers holding a person's full name, email address, and phone number can launch convincing phishing emails, SMS smishing attacks, and voice-based vishing calls. Because the data comes from a public transportation service, threat actors can craft highly believable pretexts around route alerts, refunds, or account notifications — making targets far more likely to click malicious links or hand over additional credentials.
What Was Exposed
- Email addresses
- Phone numbers
- First names
- Last names
Why This Matters
Personal contact data is a foundational building block for identity theft and fraud. With a verified name, email, and phone number, criminals can attempt to take over accounts at other services through social engineering of support teams, submit fraudulent applications in a victim's name, or sell the aggregated records to other threat actors. The public-service nature of Kavim means many affected users may be elderly or less technically sophisticated — populations that are disproportionately targeted by phone and email scams.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a backend data store — typically by exploiting a vulnerability such as SQL injection, misconfigured database permissions, or compromised administrative credentials. Once inside, the attacker can silently export thousands or millions of records in minutes. The stolen data is then packaged and distributed on dark web forums, sold to other criminals, or used directly for follow-on attacks. Because the extraction happens at the database layer, standard application-level protections like login rate limiting offer no defense once access is established.
Check If You Are Affected
HEROIC's free scanner searches across more than 400 billion exposed records to tell you whether your email address appeared in the Kavim breach or any other known data leak. Enter your email at heroic.com to get your free exposure report instantly.
Breach Breakdown
28,783 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds