Zoomcar Data Breach Exposes 3.5M Indian Car Rental Customer Records
HEROIC's DarkHive system discovered the Zoomcar breach, exposing 3,588,582 records in July 2018. This Indian self-drive car rental platform suffered a database compromise that revealed extensive user profile information including email addresses, IP addresses, phone numbers, first and last names, and bcrypt password hashes belonging to millions of Indian mobility platform customers.
Why This Is Dangerous
Mobility and transportation platform breaches expose highly actionable personal data combining identity information with contactable credentials, enabling sophisticated social engineering attacks that impersonate legitimate transportation services. The combination of phone numbers, full names, and email addresses creates complete identity profiles that enable SIM swapping attacks and targeted SMS phishing campaigns against Indian mobile users. With over 3.5 million records, this breach represents a large-scale exposure of Indian consumer identity data that fuels targeted fraud at scale.
What Was Exposed
- Email Address
- IP Address
- Phone Number
- First Name
- Last Name
- Password Hash (bcrypt)
Why This Matters
Zoomcar customers whose data was exposed face identity theft risk driven by the combination of full name, phone number, and email that enables SIM swap fraud, targeted phishing, and account takeover across Indian financial and commercial platforms. Phone numbers combined with names from ride and car rental services are specifically exploited for impersonation fraud schemes targeting Indian banking customers through SMS and voice calls. While bcrypt hashing provides strong password protection, the surrounding identity data remains directly usable for fraud without any cracking required.
How Database Breach Works
Transportation and mobility platforms accumulate rich user profile data from identity verification requirements during vehicle rental registration, creating databases with detailed personal information beyond simple email and password pairs. Attackers target mobility platform databases for the combination of verified identity data and contact information that supports high-value fraud operations. This profile data is traded on underground markets where comprehensive identity records from verified users command higher prices than basic credential pairs.
Check If You Are Affected
HEROIC offers a free identity scanner searching over 400 billion records including data from the Zoomcar breach. Visit heroic.com to check if your information was exposed.
Breach Breakdown
3,588,582 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds