SYS::ONLINE
Wasteland.
Briefs1529
Issues20
SinceFeb 2026
LIVE
▣ Breach BLABLACAR-140M-REC 2026-07-24

BlaBlaCar: Threat Actor Claims 140M Record Breach

"A threat actor is advertising a database on a dark web cybercrime forum claiming to hold 140 million user records belonging to BlaBlaCar, the France-based carpooling and long-distance travel platform. The listing was…"

A threat actor is advertising a database on a dark web cybercrime forum claiming to hold 140 million user records belonging to BlaBlaCar, the France-based carpooling and long-distance travel platform. The listing was first surfaced by threat intelligence firm ThreatMon and has since been independently flagged by other breach-tracking outlets monitoring the same forum thread. If authentic, it would rank among the larger consumer platform breaches disclosed in 2026.

What Happened

The listing, titled "BlaBlaCar 140M," alleges the exposure of sensitive personal and account data drawn from users across BlaBlaCar's international footprint. BlaBlaCar operates in more than 22 countries, connecting drivers with unused seats to passengers traveling similar routes and serving tens of millions of active members annually.

The seller shared sample records in the forum thread to substantiate the claim. As with most dark web marketplace listings, the vendor's assertions remain unverified by the company, and researchers are still assessing whether the trove reflects a fresh intrusion or a repackaging of older data circulated under new branding.

What Was Taken

Sample records reportedly expose a broad set of personally identifiable information and platform-specific metadata. The advertised fields allegedly include:

The combination of identity data, verified phone numbers, and detailed behavioral history makes this dataset unusually rich for downstream abuse, even where passwords are hashed.

Why It Matters

The presence of bcrypt hashes slows, but does not stop, password cracking against weak or reused credentials. Paired with verified phone numbers and granular ride history, the dataset offers attackers material for credential stuffing, SIM-swapping, and highly targeted phishing that references a victim's actual trips. Trust-based ride-sharing between strangers amplifies the social engineering risk: a lure that cites a real ride, rating, or wallet balance is far more convincing than a generic scam.

The Attack Technique

No intrusion vector has been confirmed, and BlaBlaCar has not validated the claim. Security researchers reviewing the leaked samples have raised questions about provenance, with some indicators suggesting the records may date back to 2025. That ambiguity is common in these listings, where sellers repackage older, previously uncataloged breaches under new branding to maximize sale value. Whether this represents a new compromise or a rehash of prior data remains an open question, but the risk to affected users persists regardless of the data's age.

What Organizations Should Do

Sources: Threat Actor Claims BlaBlaCar Breach Exposing 140 Million User Records