Hacker hands using laptop showing car sharing platform data breach

Car Sharing Platform Zoomcar Hit by a Massive Data Breach, Impacting Approximately 8.4 Million People

Car-sharing giant Zoomcar has disclosed a data breach that impacted approximately 8.4 million people after a threat actor contacted the company claiming to have accessed its data.

India-based Zoomcar operates in approximately 100 cities across India, Egypt, Indonesia, and Vietnam, and other Asian countries, and has over 10 million users. In 2023, it was registered in the United States after merging with an American-based IOAC. With headquarters based in Delaware, the ride-sharing platform currently trades on the Nasdaq as ZCAR.

“On June 9, 2025, Zoomcar Holdings, Inc. identified a cybersecurity incident involving unauthorized access to its information systems,” the company stated in a U.S. Securities and Exchange Commission (SEC) filing. “The Company became aware of the incident after certain employees received external communications from a threat actor alleging unauthorized access to Company data.”

Upon receiving the information, Zoomcar initiated its incident response plan and launched an investigation with third-party cyber forensics, which confirmed that sensitive personal data was compromised.

Zoomcar car sharing data breach leaked personal information

Preliminary results of the ongoing investigation determined that the car-sharing data breach leaked the personal information of approximately 8.4 million people.

“Based on preliminary findings, the Company determined that an unauthorized third party accessed a limited dataset containing certain personal information of a subset of approximately 8.4 million users,” the company stated

Details leaked in the car-sharing data breach include the victims’ names, phone numbers, email addresses, car registration numbers, and home addresses.

Financial information and account login credentials, such as user passwords, were spared during the car-sharing data breach. However, the full scope of the data breach remains under investigation, and the preliminary assessment could change when more information becomes available.

“Although this was a large breach, the information compromised does not pose a direct threat to victims’ accounts or finances,” said Paul Bischoff, Consumer Privacy Advocate at Comparitech. “Victims should be on the lookout for targeted phishing messages and scams via text and email. Those messages might pretend to be from Zoomcar or a related company. Never click on links or attachments in unsolicited emails and texts.”

“First of all, bravo to Zoomcar for quickly alerting the public to the breach,” said Chris Hauk, Consumer Privacy Champion at Pixel Privacy. “Luckily, no credit card, debit card, or other financial information was exposed in the breach. However, Zoomcar customers do need to stay alert for any attempts to open new accounts in their name and to especially stay alert for phishing attempts where bad actors use the information they were able to obtain to pry more information from customers that can be used to breach accounts.”

Nonetheless, the Zoomcar cyber attack did not disrupt the car-sharing giant’s internal and customer-facing operations, thus ruling out a ransomware attack. While Zoomcar has not disclosed the attack vector the threat actor exploited, cloud misconfigurations are a leading cause of data breaches that do not involve malware.

Additionally, this is hardly the first time Zoomcar has suffered a data breach. In 2018, the car-sharing platform suffered a data breach that leaked the personal information of 3.5 million people. Threat actors behind that data heist listed the stolen information for sale on an underground hacking forum.

So far, the identity of the threat actor remains unknown, and Zoomcar has not disclosed whether a ransom was demanded or is under consideration.

Additional security measures implemented; material impact unknown

Meanwhile, the car-sharing platform has implemented additional security measures, including hardening its cloud platforms, enhancing monitoring, and reviewing its access controls.

It has also notified relevant law enforcement and regulatory authorities to comply with various data breach notification laws. It also cooperates fully with the relevant authorities to investigate the data breach and bring the perpetrators to book.

Nonetheless, it remains unclear if affected customers have been notified to enable them to protect against phishing attacks that could exploit their leaked data. Contact information, such as phone numbers and email addresses, is invaluable to cybercriminals for targeted phishing (spearphishing) attacks.

Meanwhile, the material impact of the data breach remains unknown, as the company may face financial, legal, and reputational repercussions as a result of the cyber attack.