Hackers allegedly offer data of 140 million BlaBlaCar users. The sample includes email addresses, phone numbers, and password hashes.
In a cybercrime forum, a threat actor is allegedly offering a database containing 140 million user records from the carpooling platform BlaBlaCar for sale. The French company operates in 21 countries across Europe and Latin America and states that it has more than 100 million members. An official confirmation of the incident by the company has not yet been issued. The announcement comes at a time when BlaBlaCar is preparing to expand into 20 additional markets.
Analysis of the Published Data Sample
To substantiate the claim, the seller linked a sample of 43 records, which were evaluated by security researchers from Cybernews. The sample includes information such as:
- Email addresses and phone numbers
- Passwords hashed using the bcrypt algorithm
- Account status and gender information
- Device information such as operating system and app version
- Vehicle details, such as car makes of registered drivers
Security researchers note that the combination of contact details, device information, and vehicle data can be used for targeted phishing attempts or fraudulent calls.
Doubts Regarding the Age of the Offered Data
The exact scope and timeliness of the data have not yet been independently verified. An analysis of the timestamps in the sample suggests that the breach may not be recent. A security researcher from Cybernews commented on the dataset as follows:
“I am a bit suspicious about how old this data is. The most recent dates are around 2025. However, I did not see any more posts about this, nor any news channels talking about it before.”
security resarcher from Cybernews
Whether this represents a new security incident or if older datasets are circulating again remains unclear.
(red)