Inside the RentoMojo Database Breach: How 1.75M Records Were Stolen
HEROIC analysts found over 1.75 million records from RentoMojo circulating on dark web forums in April 2023. The dataset surfaced during routine threat intelligence monitoring and included a broad sweep of customer account data from the Indian rental service. What made this one stand out was the combination of government document identifiers alongside standard PII, pointing to a deeper level of database access than typical credential dumps.
Database Exfiltration: How Attackers Got In and What They Took
When attackers gain direct access to a production database, they don't just grab passwords and leave. They pull everything they can reach. In the RentoMojo breach, that ment email addresses, full names, phone numbers, birthdates, and bcrypt password hashes in a single structured export. Attackers with this kind of access can cross-reference records, build detailed user profiles, and target individuals with highly convincing fraud schemes. The presence of passport and Aadhaar numbers recieved particular attention from our team, as those identifiers are extremely difficult to change once exposed.
What Was Exposed in the RentoMojo Breach
- Email addresses
- First and last names
- Phone numbers
- Dates of birth
- Passport numbers
- Aadhaar numbers
- Gender
- Purchase history
- bcrypt password hashes
Why Government ID Exposure Makes This Breach Worse
Most breaches involve credentials and contact info. This one went further. Passport and Aadhaar numbers exposed in the RentoMojo incident can be used for identity fraud, SIM swap attacks, and even loan fraud in India's digital lending ecosystem. Unlike a password, you cannot reset your Aadhaar number. Victims of this breach face long-term risk of identity theft that goes well beyond account takeover.
How Database Breach Attacks Work
A database breach typically starts with a vulnerability in a web-facing application, often SQL injection or a misconfigured API that allows attackers to query backend systems directly. Once inside, they run structured exports of user tables, capturing every field stored. In some cases, attackers use compromised admin credentials obtained through phishing or credential stuffing to log into database management tools directly. The data is then compressed, exfiltrated, and listed on dark web marketplaces, sometimes within hours of the initial access. Organizations that store sensitive PII alongside authentication data in the same tables are partcularly exposed to this type of attack.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including datasets like the RentoMojo breach. If your information was part of this or any other known leak, you'll know immediately. Run a free scan at HEROIC and take action before someone else does.
Breach Breakdown
1,750,639 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds