A serious cybersecurity incident has hit Zoomcar Holdings, with the company confirming a data breach affecting more than 8.4 million users. The revelation was made on June 9, through an email sent by the attacker to the company's employees, informing them of the attack.

While Zoomcar's services were not disrupted, an internal investigation found unauthorized access to sensitive customer data. The exposed data included names, phone numbers, license plates, home addresses and emails. According to the company, there is no indication that financial data or passwords were leaked in a human-readable form.
See also: Washington Post: Investigating breach of its journalists' emails?
Zoomcar, a peer-to-peer car rental platform with operations in Asian emerging markets, reported the data breach to the US Securities and Exchange Commission (SEC).
In a statement, the company said: “ On June 9, 2025, Zoomcar Holdings, Inc. identified a cybersecurity incident involving unauthorized access to its information systems . The Company became aware of the incident after certain employees received external communications from a threat actor claiming unauthorized access to Company data.”
The nature of the attack remains unknown, and no ransomware group has yet claimed responsibility. However, the Zoomcar data breach is concerning on several levels — not just the sheer volume of users it affected (8.4 million), but also how it was revealed: via an email from the attacker himself. That in itself shows audacity and confidence, perhaps suggesting a well-organized and experienced cybercrime group. On the other hand, the fact that the company was notified by the hacker himself, rather than through its internal detection mechanisms , is a bellwether for the effectiveness of its security measures.
See also: Texas Department of Transportation Violation
Although no financial information or passwords are included in plain text, the personal data leaked (names, addresses, license plates, etc.) is enough to enable personalized phishing attacks or other forms of social engineering.

This breach shows that even companies that are traded on international exchanges are not necessarily able to protect customers' data adequately. Beyond the legal and operational costs, Zoomcar is now being asked to manage a blow to confidence, especially in a market like India, where the car sharing ecosystem is still in its infancy.
Second violation
It's worth noting that this isn't the first Zoomcar data breach. A similar leak affected 3.5 million users in 2018. The data from that breach — including passwords, emails, and IP addresses— later ended up on an underground cyber market for sale.
See also: Sensata Technologies: Ransomware attack led to data breach
When a company is hit twice by such serious breaches, the question naturally arises: were sufficient improvements made after the first time?
The company emphasizes that it is continuing its investigation to determine the full scope of the breach and the potential impact, while refraining from commenting on further details.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
