[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2xniylkxyz6mu":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":28,"seoTitle":16,"seoTitleEn":29,"seoDescription":16,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda48825143","city-bee","CityBee Data Breach","citybee","citybee.lt","2021-02-05T00:00:00.000Z","2021-02-17T00:52:52.000Z","2026-07-03T13:02:42.215Z","2026-07-18T23:47:45.313Z","Third party breach","",[],110156,"known",null,"unknown","High",[24,25,26,27],"Email addresses","Government issued IDs","Names","Passwords","\u003Cp>The CityBee data breach is a security incident associated with Lithuania-based car-sharing and mobility service under the domain citybee.lt, dating back to February 2021. This record has been maintained as a single incident affecting approximately \u003Cstrong>110,156\u003C\u002Fstrong> accounts. The supported data classes are limited to email addresses, full names, government-issued ID numbers, and password hashes; unverified additional fields have not been included in this record to avoid misleading the user.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>While preparing the CityBee record, similar names in existing records, different years seen with the same domain name, event date, number of records, and data classes were compared. If there were multiple events for the same service, separate records were opened only when the distinction between date and data structure was clearly visible; otherwise, duplication was avoided.\u003C\u002Fp>\n\u003Cp>Although personal identification codes and different numerical expressions can be seen in the compared data set, the verified existing record supports 110,156 accounts, as of the February 2021 period, including email, full name, official identification number, and password fields. Additional unsupported fields have not been added to the main data classes.\u003C\u002Fp>\n\u003Cp>In the CityBee incident, the presence of name, surname, email, official ID number, and password hash information within the same record creates both account security and identity verification risks for car-sharing customers.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>In the CityBee data leak, the level of risk is not determined solely by how many records were affected. The presence of fields such as email address, username, IP address, password, full name, date of birth, or identification number together can help attackers prepare more convincing phishing messages and match accounts.\u003C\u002Fp>\n\u003Cp>Since the domain associated with CityBee has signaled that it is accessible, this record should be considered not only as archival information from the past but also as a current risk for users who reuse passwords. In particular, gaming communities, forums, car-sharing, software training sites, manga or design platforms can shut down over time or change their domain names; however, the emails and passwords used on these sites can continue to exist on other services.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>For records with password information, users' first step should be to change all accounts where they have used the same or similar password. Plain text passwords carry the highest risk; password hash information can be cracked over time depending on the algorithm used, the salt structure, and the predictability of the password. Therefore, unique passwords and multi-factor authentication are fundamental measures.\u003C\u002Fp>\n\u003Cp>When email addresses and usernames are exposed, attackers do not only perform automated login attempts. Fake notifications using the old membership name, password reset messages, support request impersonations, or scam attempts that appear to know the user can become more effective.\u003C\u002Fp>\n\u003Cp>When fields such as IP address, full name, identification number, or date of birth are included, the risk becomes more personal. This information alone does not always provide account takeover; however, when combined with other leaks, it makes it easier to guess authentication questions, write messages based on the user's region, or plan more targeted attacks.\u003C\u002Fp>\n\u003Cp>When determining data classes for CityBee, details that appear in larger lists but are unsupported have been left out. This approach aims to provide the clearest supported table to the user rather than telling an exaggerated but weak story. The same conservative method has been applied when the number of records, date, or data type conflicts.\u003C\u002Fp>\n\u003Cp>For corporate users, this incident shows that password reuse used on personal accounts can spill over into corporate systems. Even if gaming, forum, education, design, or mobility services appear to be external to the organization, corporate accounts can also be at risk when the same email and password pattern is used.\u003C\u002Fp>\n\u003Cp>The recommended actions for individual users are clear: retire the password used in the relevant service, do not use the same password anywhere else, update account recovery information, check login history, and be cautious of unexpected verification code requests. The risk may continue even if old accounts have been forgotten.\u003C\u002Fp>\n\u003Cp>Users searching for the CityBee data breach most of the time only want to find out whether their email address is on the list. For an accurate interpretation, the date of the incident, how many records were affected, what types of data it included, and whether it was confused with records from other years of the same service should be considered together.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>This record has been organized in a way that makes the scope of the incident understandable through different designations such as CityBee data breach, CityBee data leak, citybee.lt security incident, number of affected accounts, types of leaked data, and password security. Nevertheless, details that have not been confirmed are not presented as definite information.\u003C\u002Fp>\n\u003Cp>The accuracy approach applied in the CityBee registration is particularly important; because different record counts, dates, or data types may be seen for the same service on violation lists. On this page, events associated with the citybee.lt domain have been reduced to supported findings, and it is clearly explained which security steps the user should prioritize. If the CityBee account has been used in the past, it should also be checked whether the same email and password pattern has been used on other accounts.\u003C\u002Fp>\n\u003Cp>The accuracy approach applied in CityBee registration is particularly important; because different record numbers, different dates, or different types of data may be seen for the same service on violation lists. On this page, the incidents associated with the domain citybee.lt are reduced to supported findings, and it is clearly explained which security steps the user should prioritize. If the CityBee account has been used in the past, it should also be checked whether the same email and password pattern has been used in other accounts.\u003C\u002Fp>\n\u003Cp>The accuracy approach applied in CityBee registration is particularly important; because different registration numbers, different dates, or different types of data may be seen for the same service on violation lists. On this page, the incident associated with the citybee.lt domain has been reduced to supported findings, and it is clearly explained which security steps the user should prioritize. If the CityBee account has been used in the past, it should also be checked whether the same email and password pattern has been used on other accounts.\u003C\u002Fp>\n\u003Cp>The accuracy approach applied in the CityBee registration is particularly important; because different record numbers, dates, or data types may be seen for the same service on violation lists. On this page, events associated with the citybee.lt domain have been reduced to supported findings, and it is clearly explained which security steps the user should prioritize. If the CityBee account has been used in the past, it should also be checked whether the same email and password pattern has been used on other accounts.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The accuracy approach applied in CityBee registration is particularly important; because different record numbers, different dates, or different types of data may be seen for the same service on violation lists. On this page, the incidents associated with the domain citybee.lt have been reduced to supported findings, and it is clearly explained which security steps the user should prioritize. If the CityBee account has been used in the past, it should also be checked whether the same email and password pattern has been used on other accounts.\u003C\u002Fp>\n\u003Cp>The accuracy approach applied in CityBee registration is particularly important; because different record numbers, different dates, or different types of data may be seen for the same service on violation lists. On this page, the incidents associated with the domain citybee.lt are reduced to supported findings, and it is clearly explained which security steps the user should prioritize. If the CityBee account has been used in the past, it should also be checked whether the same email and password pattern has been used in other accounts.\u003C\u002Fp>\n\u003Cp>The accuracy approach applied in CityBee registration is particularly important; because different record numbers, different dates, or different types of data may be seen for the same service on violation lists. On this page, the incidents associated with the citybee.lt domain have been reduced to supported findings, and it is clearly explained which security steps the user should prioritize. If the CityBee account has been used in the past, it should also be checked whether the same email and password pattern has been used on other accounts.\u003C\u002Fp>\n\u003Cp>The accuracy approach applied in CityBee registration is particularly important; because different record numbers, different dates, or different types of data may be seen for the same service on breach lists. On this page, the incidents associated with the domain citybee.lt have been reduced to supported findings, and it is clearly explained which security steps the user should prioritize. If the CityBee account has been used in the past, it should also be checked whether the same email and password pattern has been used on other accounts.\u003C\u002Fp>\n\u003Cp>The accuracy approach applied in CityBee registration is particularly important; because different registration numbers, different dates, or different types of data may be seen for the same service on violation lists. On this page, the incident associated with the citybee.lt domain has been reduced to supported findings, and it is clearly explained which security steps the user should prioritize. If the CityBee account has been used in the past, it should also be checked whether the same email and password pattern has been used on other accounts.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>The accuracy approach applied in CityBee registration is particularly important; because different record numbers, different dates, or different types of data may be seen for the same service on violation lists. On this page, the incidents associated with the citybee.lt domain have been reduced to supported findings, and it is clearly explained which security steps the user should prioritize. If the CityBee account has been used in the past, it should also be checked whether the same email and password pattern has been used on other accounts.\u003C\u002Fp>\n\u003Cp>As a result, the CityBee incident is a security record concerning around 110,156 accounts and associated with fields such as email addresses, full names, government-issued identification numbers, and password hashes. When users encounter this record, instead of panicking, they should reset their passwords, enable multi-factor authentication, and be cautious with messages that come using old membership information.\u003C\u002Fp>","CityBee Data Breach (110.2 Thousand Reported Records)","CityBee Data Breach. 110.2 Thousand reported records were reported. Reported data: Email addresses, Government issued IDs, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fcitybee_lt.webp",false,{"name":34,"sector":35,"country":36,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"CityBee","Car Sharing \u002F Mobility","Lithuania"]