CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

Boston police tested Motorola and Axon readers as Flock exited

Cybersecurity

Leapmotor EVs carry cameras from a supplier Australia banned

Policy & Compliance

BYD rewrites Australian privacy policy after Four Corners questions

Cybersecurity

A passwordless port let a researcher command a moving BYD ute

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

CARS24 files complaint over 3,100 customer records sold to rival

The used-car platform says roughly 3,100 customer records leaked over six months and landed with a rival paying about $12 per lead.

CarThreat Staff
Last updated: September 6, 2026 8:59 pm
By
ctadmin
2 Min Read
SHARE

CARS24 waited until this week to go to police over customer data it says had been draining out of its systems since March. The used-car platform’s complaint, filed by legal head Shyamal Anand, puts the toll near 3,100 records and names five people: Preeti, Pallavi, Kalpana, Sahil Rana, and Mohit.

Roughly 3,100 files are said to be involved, and they carried far more than phone numbers. Names, vehicle details, inspection reports, appointment schedules, pricing, and internal sales records were all reportedly inside, with leads finding their way to Punjab-based Direct-Cars and other outside dealerships.

Messages recovered during an internal review suggested a going rate of about 1,000 rupees ($12) per lead and a destination list that included Direct-Cars, a Punjab rival. CARS24 pegs its alleged losses at roughly $680K, while police have yet to confirm who moved the data or how widely it spread.

The episode underlines how vehicle-related data can leak without any firewall being breached. Staff or partners who legitimately reach a database can copy and sell what they see, and CARS24 is said to have learned of the problem only when people tied to another firm started contacting its customers. Least-privilege access, export monitoring, and append-only logs are the standard defenses for lead-heavy businesses.

No misuse of the records for fraud has surfaced so far. The real risk is social engineering: a caller who already knows a customer’s name, car, and expected price sounds convincing, so unsolicited dealer calls deserve skepticism and a direct question about where the data came from.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Connected VehiclesCybersecurityData BreachData PrivacyThreat Intelligence
SOURCES:GBHackers on Security
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

First car head unit malware hides inside Android update channel

By
ctadmin
August 22, 2026
Cybersecurity

Volvo EX60 Camera Feed Gets Real Time AI Interpretation via Google Gemini

By
ctadmin
May 24, 2026
Policy & Compliance

Carmakers’ lobby presses Congress to bar Chinese connected vehicles this year

By
ctadmin
September 5, 2026
Cybersecurity

Bidirectional EV Charging Turns Connected Cars into Grid Assets

By
ctadmin
June 5, 2026
Cybersecurity

ChargePoint and Powers Parts Partner to Solve Charging Infrastructure Bottleneck for Electric Buses

By
ctadmin
June 1, 2026
Cybersecurity

Chinese lidar faces federal review as lawmakers push bans

By
ctadmin
August 23, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • OTA Updates
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?