HEROIC Analysts Found Rappi Carga User Data Circulating After Database Breach
HEROIC analysts discovered 84,368 records from Rappi Carga circulating in dark web data markets following a database breach dated July 1, 2024. The exposed data belongs to users of the Colombian delivery platform and includes email addresses and phone numbers. The dataset was identified during routine monitoring of threat intelligence feeds and underground forums where breach data is bought and sold. Rappi Carga operates across Latin America, giving this leak a broad geographic footprint and elevating the risk for Spanish-speaking users in Colombia and beyond.
Why This Is Dangerous
Phone numbers and email addresses together form the two most exploited contact vectors in modern fraud operations. Attackers use email addresses for phishing and account takeover attempts, while phone numbers enable SMS-based smishing attacks and SIM-swap fraud. In Latin American markets, where delivery platform accounts are frequently linked to payment methods, a breach of contact data creates a direct pathway to financial fraud. The combination also enables two-factor authentication bypass, since attackers who control a phone number can intercept SMS verification codes.
What Was Exposed
- Email Address
- Phone Number
Why This Matters
Credential stuffing attacks begin with email addresses. Even without a password in this dataset, attackers cross-reference exposed emails against other breach compilations to find reused credentials, then use automated tools to test those credentials across banking, e-commerce, and delivery platforms. Phone numbers extend the attack surface further: they are used to bypass SMS-based two-factor authentication, impersonate users in social engineering calls, and register fraudulent accounts. For Rappi Carga users who link payment cards to their delivery accounts, the downstream financial risk is significant.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a backend data store through methods such as SQL injection, exploitation of unpatched vulnerabilities, compromised administrative credentials, or misconfigured cloud storage. Once access is established, the attacker exports user tables and packages the data for distribution. Delivery and logistics platforms are high-value targets because they store contact information, delivery addresses, and payment data for large, active user bases. Exfiltrated data typically surfaces on dark web forums within days to weeks of the initial compromise.
Check If You Are Affected
HEROIC's free breach scanner searches more than 400 billion compromised records to determine instantly whether your email address appears in known breach data, including incidents like this Rappi Carga leak. Run a free scan at heroic.com to see if your information is exposed and take immediate steps to secure your accounts.
Breach Breakdown
84,368 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds