[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f28ysnsqa02veg":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":30,"seoTitle":31,"seoTitleEn":32,"seoDescription":31,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":4,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda48825439","Zoomcar","Zoomcar Data Breach","zoomcar","zoomcar.com","2018-07-01T00:00:00.000Z","2020-06-05T02:57:26.000Z","2026-07-27T16:11:15.223Z","Verified breach record","https:\u002F\u002Ftech.economictimes.indiatimes.com\u002Fnews\u002Finternet\u002Fzoomcar-says-data-of-3-5-million-users-compromised\u002F76175470",[15,17,18],"https:\u002F\u002Fwww.sec.gov\u002FArchives\u002Fedgar\u002Fdata\u002F1854275\u002F000121390025054319\u002Fea0245724-8k_zoomcar.htm","https:\u002F\u002Feconomictimes.indiatimes.com\u002Ftech\u002Ftechnology\u002Fcar-rental-platform-zoomcar-users-data-leaked-in-cyberattack\u002Farticleshow\u002F121889404.cms",3589795,"known",null,"unknown","Critical",[25,26,27,28,29],"Email addresses","IP addresses","Names","Passwords","Phone numbers","\u003Cp>The Zoomcar data breach is a verified incident from July 2018 that affected users of the India-based car-sharing and driverless rental service. The verified main scope is 3,589,795 unique email accounts. The appearance of the incident later on underground sale lists does not change the incident date presented to the user; for the Zoomcar breach, the incident date should be maintained as July 2018, with the verified addition date as June 5, 2020. The affected data groups include email addresses, IP addresses, name information, phone numbers, and passwords in bcrypt hash format. Therefore, the risk should be considered linked across the car rental account, email account, and other services using the same password.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Verified data categories are email addresses, IP addresses, name information, phone numbers, and passwords. The password field should be treated as password data stored in bcrypt hash format, not as plaintext password. Although bcrypt is a strong password storage method, the risk is not completely eliminated for weak or reused passwords. If the same password is used in services involving email, transportation, payment, social media, or work accounts, attackers may target these accounts with automated login attempts.\u003C\u002Fp>\n\u003Cp>The combination of name, phone, and email generates sufficient context for targeted phishing. When a relationship with a car rental service can be established, messages themed around fake reservations, payment confirmations, driving documents, security notifications, or support requests may appear more convincing. An IP address alone is not definitive proof of location; however, when combined with account activity, it provides additional traces. Physical address, payment card, official ID, driver's license image, vehicle registration document, or travel history are not among the verified data categories for this 2018 record.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>For the Zoomcar incident, the scope of LeakData should be kept as 3,589,795 unique email accounts. The date of the breach should be tracked as July 1, 2018, with the verified addition time recorded as June 5, 2020. Numbers and data fields mentioned in wider news or Zoomcar incidents from different years should not be added to this 2018 record. This distinction is particularly important; separate incidents can occur for the same brand on different dates, but each incident should be evaluated with its own verified date and data category.\u003C\u002Fp>\n\u003Cp>The verified data fields of this record are email addresses, IP addresses, names, passwords, and phone numbers. The password description should be stored as a bcrypt hash and should not be described as a plaintext password. Payment information, bank account, official ID, driver's license file, vehicle registration number, physical address, or real-time location history should not be included among the proven fields for this incident. Providing a clear boundary to the user reduces false alarms and keeps the necessary security steps in focus.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk is for users who reuse the password they use for their Zoomcar account on other accounts. When an email address and phone number are both available, attackers can send fake support, reservation, promotion, or debt notifications via both email and SMS. Name information personalizes the messages; the IP address, on the other hand, can provide additional clues about the technical context of the account. Therefore, an old car rental account can affect the security of currently active email and mobile accounts.\u003C\u002Fp>\n\u003Cp>People using Zoomcar with a corporate email address may be more susceptible to social engineering attempts related to travel and fleet operations. For those who create an account with a personal email address, password reuse, fake delivery, or fake booking messages are more prominent. Since a phone number is provided, caution should be exercised against SIM swapping, fake support calls, and attempts to request verification codes. A user with a positive match should not consider the fact that the old account is no longer in use as sufficient protection on its own.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>A user with an email address in Zoomcar data must first ensure that the old password used in the Zoomcar account is not valid for any other account. If the same or similar password has been used in email, banking, social media, transportation, shopping, or work accounts, a separate and long password should be set for each account. Using a password manager reduces the risk of reuse. Changing a small part of the password or adding a date at the end is not sufficient; the old pattern must be completely abandoned.\u003C\u002Fp>\n\u003Cp>Two-factor authentication should be enabled for services linked to your email account and phone number. If you receive an unexpected reservation, payment, damage fee, driving document, or account security message, you should use the official app or website directly instead of clicking a link. Verification codes received via SMS should not be shared with anyone. If there is a suspicious session, an unexpected password reset request, or an unknown device notification, sessions should be closed, recovery information reviewed, and other transportation accounts opened with the same email should be checked.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Zoomcar breach shows that transportation and rental accounts need to be protected as much as primary identity accounts. Users should avoid reusing passwords across personal, work, financial, transportation, and social media accounts. Since phone numbers and email addresses do not change for many years, old breach data can regain value in new phishing campaigns. Unused transportation accounts should be closed or isolated with unique passwords and multi-factor protection.\u003C\u002Fp>\n\u003Cp>The key lesson for service providers is to protect password hashes with strong methods, regularly audit access logs, minimize unnecessary personal data fields, and provide breach notifications without delay. Since additional sensitive areas such as payment, identity, and vehicle documents may exist in car-sharing services, the incident report should clearly distinguish which areas were affected and which were not. In this 2018 Zoomcar case, risk communication should focus on account security, phone-based fraud, and phishing.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>As a result of the record check for a Zoomcar violation, it shows whether the entered email address is found in this verified dataset. If the result is positive, the email address, IP address, name information, phone number, and bcrypt password hash should be considered at risk. If the result is negative, it only means that no match was found in this specific dataset; this does not prove that the person has not been involved in other Zoomcar incidents or violations of other transportation services. Keeping accurate dates prevents confusion between older incidents and statements from different years.\u003C\u002Fp>\n\u003Cp>The correct action is to completely abandon the old password, change all reused passwords, enable multi-factor protection for the email account, and be cautious against fake support or reservation messages received via phone number. The user should also review transportation, car rental, payment, and social media accounts opened with the same email and phone number. This way, the risk of a 2018 data breach turning into account takeover, targeted phishing, or phone-based fraud today is reduced.\u003C\u002Fp>","","Zoomcar Data Breach (3.6 Million Reported Records)","Zoomcar Data Breach. 3.6 Million reported records were reported. Reported data: Email addresses, IP addresses, Names. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fzoomcar_com.webp",false,{"name":7,"sector":37,"country":38,"website":10,"websiteArchiveUrl":31,"websiteStatus":31,"websiteCheckedAt":21},"Car sharing and self-drive rental","India"]