Massive Europcar data breach affects around 200,000 customers

 Massive Europcar data breach affects around 200,000 customers

Published on April 7, 2025 | Category: tech

Massive Europcar data breach affects around 200,000 customers

News
By Sead Fadilpašić published

Europcar's GitHub account was compromised

Abstract image of cyber security in action.
OpenVPN-protokollet - därför är det så bra (Image credit: Shutterstock)

  • Cybercriminal advertises stolen archive on an underground forum
  • It was confirmed to have come from car rental giant Europcar
  • The company is now investigating and notifying the customers

Europcar has reportedly suffered a data breach in which it lost sensitive data on hundreds of thousands of customers.

A threat actor with the alias 'Europcar' posted a new thread in an underground forum, claiming to have “successfully breached Europcar’s systems and obtained all their GitLab repositories”.

As a result, the attacker took more than 9,000 SQL files from the repository, containing sensitive personal data, as well as at least 269 .ENV files, which are used to store configuration settings for apps, and more.

Monitor your credit score with TransUnion starting at $29.95/month

Monitor your credit score with TransUnion starting at $29.95/month

TransUnion is a credit monitoring service that helps you stay on top of your financial health. With real-time alerts, credit score tracking, and identity theft protection, it ensures you never miss important changes. You'll benefit from a customizable online interface with clear insights into your credit profile. Businesses also benefit from TransUnion’s advanced risk assessment tools.

Preferred partner (What does this mean?)

View Deal

Names and emails stolen

The company later confirmed the breach to BleepingComputer, saying it is assessing the damage and notifying affected individuals. It also said that it is not true that its entire repository was compromised - a small part of the source code was not stolen, apparently.

We don’t know exactly what kind of information the hacker stole, but initial reports mention names and email addresses of Goldcar and Ubeeqo users, generated between 2017 and 2020. Payment information was not exposed, however.

The publication also reported that the threat actor wanted to extort the company, but did not clarify if Europcar paid the ransom demand or not. It seems it didn’t.

The information is currently ongoing and it's not known exactly how the hackers compromised Europcar’s GitHub account. They could have stolen the credentials via phishing, infostealer malware, or with brute force. The first two options are more viable.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

GitHub, being one of the world’s most popular open source code repositories, is a major target for cybercriminals.

Oftentimes, they would spoof popular repositories and infect them with infostealers, tricking developers into downloading the wrong package and compromising their infrastructure. Developers are urged to be careful, to always double-check repository names, to read through the reviews and the comments.

Via BleepingComputer

You might also like

  • Europcar denies data breach affecting 50 million customers — says ChatGPT is to blame in creating fake data
  • We've rounded up the best password managers
  • Take a look at our guide to the best authenticator app
TOPICS
Sead Fadilpašić

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

More about security
Padlock against circuit board/cybersecurity background

8 signs your company needs to upgrade its cybersecurity

Microsoft

Look out for tax-themed scams this month, Microsoft warns

Latest
art of a human hand with artificial intelligence via laptop

Businesses are getting more confident about AI

See more latest
Most Popular
art of a human hand with artificial intelligence via laptop
Businesses are getting more confident about AI
JMGO N1S 4K projector
This 4K portable laser projector goes twice as bright, twice as big as LG's equivalent, for the same price
Christopher Smith giving a thumbs up with a car on fire in the background in Peacemaker season 2
Peacemaker season 2 release date finally confirmed as new footage of popular HBO TV show revealed in Max sizzle reel trailer
Campfire Audio Axion earphones
One of the most elite audiophile earbuds makers has a smart new USB-C Hi-Res pair for a much more realistic price
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
China has spent billions of dollars building far too many data centers for AI and compute - could it lead to a huge market crash?
Apple iPhone 16 Review
Leaked dummy unit image shows how thin the iPhone 17 Air may look against the iPhone 17 Pro
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, April 7 (game #400)
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, April 7 (game #1169)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, April 7 (game #666)
KTC H27P3 5K monitor
This is the cheapest 5K monitor to launch in 2025 but that's not the reason why it is so special

Related Articles

Spotify is about to be flooded with AI-made ads, and I wonder if it will make much of a difference to businesses

Spotify’s new AI-powered ad tool may not be the solution they claim....

Read More
CinemaCon 2025 live – first Avatar 3 reaction, juicy Fantastic Four news,

CinemaCon 2025 is officially underway – here are all new movie announc...

Read More
NYT Wordle today — answer and my hints for game #1385, Friday, April 4

Looking for Wordle hints? I can help. Plus get the answers to Wordle t...

Read More