A popular mobile parking app called ParkMobile has suffered a data breach. What’s the result? Personal information related to 21 million of the app’s customers is being sold online. Those customers use ParkMobile to find available parking spaces and pay for them without having to run to the parking meter every few minutes.

In his blog KrebsOnSecurity, Brian Krebs noted the extent of the data available for sale. The data includes the app's customers' emails, phone numbers, license plate numbers, customer dates of birth, mailing addresses, and hashed passwords. Information about the data breach came to light thanks to Gemini Advisory.
See also: Celsius breach led to phishing attack
According to Krebs, “Gemini shared a new sales thread on a Russian-language criminal forum that included my ParkMobile account information in the accompanying screenshot of the stolen data. The data included my email and phone number, as well as the license plate for four different vehicles we used over the past decade.”
On March 26, ParkMobile informed subscribers that it had identified “a security breach linked to a vulnerability in third-party software we use. In response, we immediately launched an investigation with the assistance of a leading cybersecurity firm to address the incident. We have also notified the appropriate law enforcement authorities. The investigation is ongoing and unfortunately we are unable to provide you with further details at this time.”
See also: Dating app Manhunt suffers serious data breach
ParkMobile told concerned users that no credit card information was stolen. In an initial statement, the company said, “Our investigation indicates that no sensitive data or payment card information, which we encrypt, was affected.”
ParkMobile initially posted an update on its website stating that it was a data breach. While the company did not initially suggest that users change their passwords, that would have been the wisest move.
The information obtained from ParkMobile customers was offered for sale at a price of $125,000.
See also: Booking.com: Fined €475,000 for failing to report data breach in a timely manner
A week ago, ParkMobile updated its post again and added the following: “Our investigation concluded that they had access to encrypted passwords, but not the encryption needed to read them. While we protect user passwords by encrypting them with advanced hashing and salting technologies, as an added precaution, users may consider changing their passwords in the “Settings” section of the ParkMobile app.
Our investigation confirmed that basic user information was stolen – license plate numbers and, if provided by the user, email and/or phone numbers. In a small percentage of cases, mailing addresses were affected. No credit cards were stolen and we do not collect social security numbers, license plates or dates of birth.
Please be assured that we take our responsibility to safeguard the security of our users' information seriously and appreciate your continued trust.”
Information source: phonearena.com
