[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f17fv6wym3386d":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":23,"affectedCountUnit":24,"hasEnglishDescription":4,"severity":25,"dataClasses":26,"description":34,"seoTitle":35,"seoTitleEn":36,"seoDescription":35,"seoDescriptionEn":37,"logoUrl":38,"isVerified":4,"isSensitive":39,"isSpamList":39,"isMalware":39,"company":40},"68e3266eda11adda48825302","ParkMobile","ParkMobile Data Breach","parkmobile","parkmobile.io","2021-03-21T00:00:00.000Z","2021-04-30T03:07:24.000Z","2026-07-19T18:18:58.750Z","Verified breach record","https:\u002F\u002Fsupport.parkmobile.io\u002Fhc\u002Fen-us\u002Farticles\u002F36854685401243-Update-Security-Notification-March-2021-Settlement",[15,17,18,19,20],"https:\u002F\u002Fsupport.parkmobile.io\u002Fapi\u002Fv2\u002Fhelp_center\u002Fen-us\u002Farticles\u002F36854685401243.json","https:\u002F\u002Fkrebsonsecurity.com\u002F2021\u002F04\u002Fparkmobile-breach-exposes-license-plate-data-mobile-numbers-of-21m-users\u002F","https:\u002F\u002Fparkmobile.io\u002F","https:\u002F\u002Fa-us.storyblok.com\u002Ff\u002F1022690\u002F4267x953\u002F779edc52e2\u002Fparkmobile_arrive_rgb.png",20949825,"known",null,"unknown","Critical",[27,28,29,30,31,32,33],"Email addresses","Licence plates","Names","Passwords","Phone numbers","Physical addresses","Vehicle details","\u003Cp>\u003Cstrong>The ParkMobile data breach\u003C\u002Fstrong> exposed contact, licence-plate, vehicle and bcrypt password-hash data for 20,949,825 users in March 2021.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The validated data classes are email addresses, names, phone numbers, vehicle licence plates, bcrypt password hashes, physical addresses and vehicle details. Physical addresses appeared for only a small percentage of users, while vehicle details included a vehicle nickname when one had been provided. Passwords were not clear text; the exposed values were bcrypt hashes that had been salted. Bcrypt slows offline guessing, but it does not make weak or short passwords risk-free. Combining email, phone, licence-plate and vehicle information can make fake parking-ticket, payment, vehicle-registration or support messages more credible. The official investigation said credit-card data and parking transaction history were not accessed, and that the service did not collect Social Security numbers, driver's licence numbers or dates of birth.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>ParkMobile said it became aware in March 2021 of a cybersecurity incident linked to a vulnerability in third-party software and quickly eliminated the weakness. The company issued an initial notice on 26 March, engaged external security specialists and notified law enforcement. Its subsequent investigation confirmed access to basic user information and password hashes. Data for roughly 21 million customers was later offered on a criminal forum and then redistributed widely; the validated corpus contains 20,949,825 unique account records. Password fields were bcrypt hashes, and the company said it protected them with hashing and salting technologies. Independent examination observed mailing addresses in some records and licence plates associated with multiple vehicles.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People who created an account before March 2021 through ParkMobile or a city- or operator-branded white-label application are directly affected. Those who reused the same password elsewhere, chose a short or predictable password, or left multi-factor authentication disabled on email face greater account-takeover risk. A licence plate and vehicle nickname provide convincing context for fake parking fines, time-extension notices or refund messages. Users whose phone number was present may receive phishing by text or voice, while the smaller group with mailing addresses may face fraudulent invoices or physical correspondence. A licence plate by itself does not reveal a vehicle's live location, and parking transaction history was not among the accessed data. Even when a name or address is absent, other validated fields may still have been exposed.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>\u003Cstrong>If you reused your 2021 ParkMobile password elsewhere, change the passwords on those accounts immediately.\u003C\u002Fstrong> Generate a long, unique password for every service, store it in a reputable password manager and enable multi-factor authentication, especially on email. If the ParkMobile account remains active, use the official application or domain to review the current login method and recovery details; do not sign in through a message link. Check unexpected parking fines, time-extension requests, vehicle-verification prompts, licence-plate updates or refund notices inside the application. Although card data was not accessed in this incident, criminals can still use the event to direct users to fake payment pages; do not provide a security code or password without independent verification. If you notice suspicious access, close active sessions and replace passwords derived from the same pattern.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Using a different password for every online service prevents one cracked bcrypt hash from unlocking unrelated accounts. A password manager makes long random values practical, while multi-factor authentication prevents an exposed password from being sufficient on its own. Keep email recovery options current, enable new-session alerts and review unfamiliar forwarding rules. Remove unused vehicles, old licence plates and outdated contact details from mobility accounts, and close accounts that are no longer needed. Parking and transport services should maintain an inventory of third-party components, track patches and limit access, while monitoring large exports and unusual queries. Password systems should use a unique salt for every user, suitable cost parameters and a policy for rehashing as hardware improves.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>\u003Cstrong>Check your email address with LeakData\u003C\u002Fstrong> to see whether it matches the ParkMobile record or another known breach. A match does not mean that your credit card or parking history was exposed; it indicates that the address appeared in the validated account dataset. Base your response on the seven listed data classes and do not infer fields excluded by the official investigation. If there is a match, determine whether the password used in 2021 was reused elsewhere, and secure email and payment-connected accounts first. Review recent parking, licence-plate, refund and fine messages, and open the official application instead of following embedded links. Keep unique passwords, multi-factor authentication and independent verification of suspicious payment links as continuous safeguards.\u003C\u002Fp>","","ParkMobile Data Breach (20.9 Million Reported Records)","ParkMobile Data Breach. 20.9 Million reported records were reported. Reported data: Email addresses, Licence plates, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fparkmobile-official.webp",false,{"name":41,"sector":42,"country":43,"website":10,"websiteArchiveUrl":35,"websiteStatus":35,"websiteCheckedAt":23},"ParkMobile, LLC","Technology","United States"]