Skip to content
cisonews.net

Incident · 8-K Item 1.05

Zoomcar reports access to personal data of about 8.4 million users

Compiled 2026-09-27 from public records. By the cisonews.net Desk.

Zoomcar Holdings, a car-sharing marketplace operating mainly in India, disclosed on June 13, 2025 that an unauthorized third party had accessed personal information of a subset of approximately 8.4 million users. The company identified the incident on June 9 after employees received messages from a threat actor claiming access to company data.

What Zoomcar reported

The dataset included names, phone numbers, car registration numbers, addresses and email addresses. Zoomcar said it had seen no evidence that financial information or plaintext passwords were compromised.

The company described added safeguards across its cloud and internal network, more monitoring and an access review, and said it had informed regulators and law enforcement.

Unknowns

The filing does not say how the third party got in, and it does not reach a view on financial materiality beyond saying the evaluation continued.

Sources

  1. 2025-06-13 · AZoomcar Holdings, Inc., Form 8-K (SEC EDGAR), published June 13, 2025

Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.

See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.