Zoomcar discloses breach affecting 8.4 million users

Organization
Zoomcar Holdings, Inc.
Exploit
Hacking
Industry
Transportation

Zoomcar Holdings, the Bengaluru based car sharing company listed in the United States, said it identified a cybersecurity incident on June 9, 2025 after a threat actor emailed employees claiming to have breached its systems and taken user data.

The company reported the intrusion in a filing with the U.S. Securities and Exchange Commission and put the number of affected users at approximately 8.4 million. The exposed details included names, phone numbers, email addresses, home addresses and vehicle registration numbers.

Zoomcar said it found no evidence that financial information or plaintext passwords were taken, and that there was no material disruption to its services. It engaged an outside cybersecurity firm, increased system monitoring, notified law enforcement and regulators, and told investors it expected reputational and remediation costs rather than an operational impact.

No ransomware group claimed responsibility, and the method of initial access was not disclosed. It was the company's second significant breach. An incident in 2018 exposed records on between 3.5 and 3.6 million customers, including names, email addresses, internet protocol addresses, phone numbers and hashed passwords, which were later offered for sale on underground forums. Zoomcar operates in 99 Indian cities and says it has more than 10 million users.

Sources