Skip to main content
Back to overview
Medium

Europcar GitLab breach exposes data of up to 200,000 customers

A hacker breached the GitLab repositories of Europcar Mobility Group, stealing source code for Android and iOS applications, as well as personal information (names and email addresses) belonging to up to 200,000…

Key points

  • Up to 200,000 customers affected.
  • GitLab repositories breached.
  • Stolen data includes source code for mobile applications, names, and email addresses.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Confidentiality impact

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality

Published
Apr 4, 2025
Updated
Jun 26, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch exposure paths that could affect data, operations or third-party trust.

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

EuropcarData DisclosureEuropcar GitLabGitLabEuropcar Mobility GroupAndroid andGoldcar and UbeeqoEuropcarStolen

Quick context

Questions about this signal

What happened in this signal?

A hacker breached the GitLab repositories of Europcar Mobility Group, stealing source code for Android and iOS applications, as well as personal information (names and email addresses) belonging to up to 200,000 customers. The affected data primarily related to its Goldcar and Ubeeqo brands. The attacker attempted to extort the company, but Europcar stated that no financial information or passwords were compromised. The incident occurred in late March 2025, with disclosure on April 4, 2025.

When was this signal reported?

Shadow Tier lists Apr 4, 2025 as the signal date.

Which organization is connected to this signal?

Europcar is the organization connected to this public signal.

Explore Europcar
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence