Car rental company Europcar is denying claims of a data breach. A hacker claimed to have sold the personal information of 50 million customers, but the company says the leaked data is fake.

It all started on Sunday, when an individual claimed to be selling the data of 48,606,700 Europcar.com customers. The posting on the hacking forum included samples of the stolen data for 31 alleged Europcar customers. The data included names, addresses, dates of birth, driver's license numbers and other details.
However, the company told BleepingComputer that the breach was fake and that the data was fabricated using artificial intelligence.
See also: Keenan & Associates: Data breach affects 1.5 million customers
“After being alerted by an intelligence agency that an account was pretending to sell Europcar data on the dark web, we thoroughly checked the data contained in the sample and are confident that this advertisement is false:
– the number of registrations is completely incorrect and inconsistent with ours,
– the data samples are likely generated by ChatGPT (addresses do not exist, zip codes do not match, first and last names do not match email addresses, email addresses use very unusual TLDs),
– and most importantly: none of these email addresses exist in our database.”.
Troy Hunt, creator of the well-known site Have I Been Pwned, also says that much of the Europcar data is clearly fake, but he doesn't believe it was created using artificial intelligence. And Hunt pointed out that the email addresses don't match the usernames.
See also: Southern Water – data breach: Black Basta ransomware gang leaked data
The second indication that the data is fake is that the addresses simply don’t exist. For example, two of the registered records use the non-existent cities “Lake Alyssaberg, DC” and “West Paulburgh, PA.”
There are also inaccuracies and mismatches in the addresses and phone numbers posted by the scammer.
However, Hunt does not believe AI was used to generate the data , as some of the email addresses are real and have appeared in previous data breaches tracked by Have I Been Pwned.
Artificial intelligence is used by cybercriminals, but in this case, things probably didn't turn out that way.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
It's a good thing that this breach is fake, though, because a real data breach has significant consequences for a company. One of them is financial damage. This can include the cost of restoring security systems, losses due to business interruption, and lawsuits from customers.
See also: Jason's Deli: Customer data breach via credential stuffing

Another important consequence is the trust customer. When customer personal data is leaked, customers become frustrated and may leave the company.
Additionally, there may be legal penalties. Customers may sue for data breaches, and regulators may impose fines for violating privacy regulations.
Finally, a data breach can have serious repercussions on a company’s reputation. Disclosure of the incident can cause negative publicity and lead to long-term damage to the company.
Source: www.bleepingcomputer.com
