CARS24 waited until this week to go to police over customer data it says had been draining out of its systems since March. The used-car platform’s complaint, filed by legal head Shyamal Anand, puts the toll near 3,100 records and names five people: Preeti, Pallavi, Kalpana, Sahil Rana, and Mohit.
Roughly 3,100 files are said to be involved, and they carried far more than phone numbers. Names, vehicle details, inspection reports, appointment schedules, pricing, and internal sales records were all reportedly inside, with leads finding their way to Punjab-based Direct-Cars and other outside dealerships.
Messages recovered during an internal review suggested a going rate of about 1,000 rupees ($12) per lead and a destination list that included Direct-Cars, a Punjab rival. CARS24 pegs its alleged losses at roughly $680K, while police have yet to confirm who moved the data or how widely it spread.
The episode underlines how vehicle-related data can leak without any firewall being breached. Staff or partners who legitimately reach a database can copy and sell what they see, and CARS24 is said to have learned of the problem only when people tied to another firm started contacting its customers. Least-privilege access, export monitoring, and append-only logs are the standard defenses for lead-heavy businesses.
No misuse of the records for fraud has surfaced so far. The real risk is social engineering: a caller who already knows a customer’s name, car, and expected price sounds convincing, so unsolicited dealer calls deserve skepticism and a direct question about where the data came from.