[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3av5m7timontd":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":36,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda4882519c","dunzo","Dunzo Data Breach","dunzo.com","2020-06-19T00:00:00.000Z","2020-07-29T04:38:23.000Z","2026-07-09T22:04:20.372Z","2026-07-18T23:49:55.815Z","Third party breach","https:\u002F\u002Fwww.medianama.com\u002F2020\u002F07\u002F223-dunzo-data-breach-2\u002F",[15,17,18],"https:\u002F\u002Findianexpress.com\u002Farticle\u002Ftechnology\u002Ftech-news-technology\u002Fdunzo-breach-explained-personal-data-of-millions-users-exposed-6530696\u002F","https:\u002F\u002Fblackkite.com\u002Fblog\u002Fmajor-third-party-data-breaches-revealed-in-july-2020",3465259,"known",null,"unknown","Critical",[25,26,27,28,29,30],"Device information","Email addresses","Geographic locations","IP addresses","Names","Phone numbers","\u003Cp>The Dunzo data breach is related to customer data that was subject to unauthorized access through third-party systems on the India-based fast delivery platform during the June 2020 period. The record contains 3,465,259 unique email addresses. Verified data fields include device information, email addresses, geolocation information, IP addresses, names, and phone numbers. In this incident, passwords, payment cards, bank accounts, official IDs, or order history are not verified data categories. The focus of the risk is contact information, device\u002Fnetwork context, and the potential tricking of delivery service users with targeted messages.\u003C\u002Fp>\n\u003Cp>The Dunzo incident demonstrates how third-party access on delivery platforms can pose risks to customer data. In the company's publicly disclosed statements, it was indicated that financial data such as payment cards were not stored and were unaffected. Nevertheless, the combination of email, phone, name, IP, and location fields can create serious privacy implications. Attackers could use this information in fake delivery notifications, account verification, promotions, returns, or customer service scenarios. Therefore, the incident should be treated not as a password leak but as a communication and profile data leak.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The verified data types are device information, email addresses, geographic location information, IP addresses, names, and phone numbers. When phone and email are together, targeted fraud can be carried out via text message, call, and email. Name information personalizes the message. IP address and geographic location fields can provide context about the user's approximate area or the city where the service is used. Device information can give an additional clue about the type of device or technical profile being used.\u003C\u002Fp>\n\u003Cp>In this case, since a password leak has not been confirmed, the direct risk of account takeover is more limited compared to password breaches. However, communication and location data are strong in terms of social engineering. An attacker may request additional information from the user under the pretext of changing the delivery address, refunding a payment, order delay, campaign code, or account update. For users with a phone number, fake calls and text messages pose a higher risk. The geographic context can make the message appear appropriate to the area where the user lives or receives services.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified incident date is tracked as June 19, 2020, and the record was added to the verified breach lists on July 29, 2020. The number of affected unique emails is 3,465,259. Some news reports may cite figures around 3.4 million, 3.5 million, or higher; this page is based on the number of verified unique emails used in the query. It has been confirmed that the dataset was circulated on online forums and associated with Dunzo data.\u003C\u002Fp>\n\u003Cp>The scope should not be expanded. In this record, password, payment card, bank account, official ID, physical address, order content, medicine purchases, or detailed delivery history are not verified data classes. The geographical location field does not mean that there are exact GPS coordinates for each user; this field can also refer to a more limited area or location context. Therefore, users should not be led to believe that the exact delivery address or detailed order history is within the verified scope. The correct risk involves using communication, device, IP, and location data together.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk group consists of customers who use delivery, grocery, package, or intra-city services through Dunzo. Users with a phone number and email address can be targeted with fake delivery updates or customer service calls. Name and location context can make the message appear to be based on real service history. For individuals using the same phone number across different delivery and shopping accounts, the risk of cross-targeting increases.\u003C\u002Fp>\n\u003Cp>Users who have received services in cities where Dunzo is active in India may be more visible. IP and device information can help the attacker personalize the message according to a specific device or regional context. Since the password has not been verified, the initial focus should not be on changing the password, but on recognizing fake communications. However, if the password used in the Dunzo account is weak on other platforms, it is recommended to use a unique password and additional verification for overall account security. This incident is particularly important in terms of phone scams and SMS-themed phishing.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Unexpected delivery, return, campaign, account verification, or payment correction messages coming under the name Dunzo should be taken into consideration. Even if your name, phone number, or location appears correctly in the message, this is not proof of security. Instead of clicking on the link, you should log into the relevant account directly through the official address or app. If people calling by phone ask for card number, bank information, one-time code, password, or identity document, the process should be stopped.\u003C\u002Fp>\n\u003Cp>Two-factor authentication should be enabled on the email account, and spam and fraud filters should be used on the phone line. The visible information and communication preferences on the Dunzo account can be reviewed. Since a password leak has not been confirmed in this incident, a mass password panic is not necessary solely because of this record; however, using a unique password for critical accounts that use the same email is still a good security measure. Payment requests and account verification steps should also be separately checked in all messages associated with delivery platforms.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>In the long term, phone and email information used in delivery and shopping accounts should be regularly reviewed. Using a separate address instead of the main email for campaigns and delivery services can reduce the impact of data leaks on main accounts. Phone numbers should not be shared in unnecessary accounts, old accounts should be closed, and visible profile fields should be minimized. It should not be forgotten that technical fields such as IP, device, and location are also personal data.\u003C\u002Fp>\n\u003Cp>From the perspective of platform operators, the Dunzo incident shows that granting access to third-party systems poses a direct risk to customer data. Supplier accesses should be limited, access to customer data should be managed with the principle of least privilege, high-volume export activities should be monitored, and communication data such as phone\u002Femail should not be kept unnecessarily. Even if payment data is unaffected, misuse of communication and location data seriously undermines user trust.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If you see a match in this record, your email address may have been found among 3,465,259 unique emails associated with the Dunzo data breach. A match does not mean that your password, payment card, or order history has been leaked. Verified fields are device information, email, geographic location, IP address, name, and phone number. The first step is to evaluate delivery-themed messages sent to this email and phone number more carefully.\u003C\u002Fp>\n\u003Cp>Do not directly open links sent on behalf of Dunzo or similar delivery platforms; check your account through the official channel. Do not share one-time codes, card information, or passwords in payment, refund, or account verification requests received by phone. The correct approach to a Dunzo data breach is not to panic over unverified password or order history claims, but to acknowledge that communication and location data could be used in targeted fraud and to strengthen message security.\u003C\u002Fp>","","Dunzo Data Breach (3.5 Million Reported Records)","Dunzo Data Breach. 3.5 Million reported records were reported. Reported data: Device information, Email addresses, Geographic locations. Review the scope…","\u002Fuploads\u002Flogo\u002Fdunzo_com.webp",false,{"name":38,"sector":39,"country":40,"website":9,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":21},"Dunzo","Technology","India"]