Used-car platform CARS24 has alleged that confidential information belonging to approximately 3,100 customers was stolen and supplied to a rival business and outside dealers. The company claims that leads were offered for about ₹1,000 each, resulting in an estimated commercial loss of ₹5.70 crore.
The complaint was filed at a Cyber Crime Police Station by CARS24 legal head Shyamal Anand. Five people, Preeti, Pallavi, Kalpana, Sahil Rana and Mohit, have been named in the FIR. CARS24 alleges that customer and business data was taken between March and August, then supplied to Punjab-based Direct-Cars.
The allegations have not been proven. Police are investigating how the records allegedly left CARS24 systems, who accessed them, and whether additional dealers received the data.
CARS24 Data Breach Exposes 3,100 Customer Records
The dataset reportedly extended beyond phone numbers. According to the420, it contained customer names, mobile numbers, vehicle details, appointments, inspection reports, pricing information, sales leads and internal business records.
In the used-car market, this intelligence is commercially valuable. A dealer with a lead knows an individual is already considering the sale or purchase of a specific vehicle, possibly including an expected price and a scheduled inspection.
Rather than paying to advertise and qualify prospects, the dealer can contact the customer directly and offer a better deal.
CARS24 said an internal inquiry uncovered WhatsApp conversations that purportedly showed leads being distributed for roughly ₹1,000 apiece.
Its ₹5.70 crore estimate reflects business it believes was lost due to the alleged diversion; the police have not independently verified the amount. The company reportedly discovered the issue after people connected with another business contacted CARS24 customers.
The case highlights a distinction: a breach does not necessarily mean an external actor penetrated a firewall. A staff member, contractor, or partner who legitimately accesses a database but copies, shares, or sells information without permission can cause a data breach.
Investigators can examine account permissions, login histories, downloads, export events, device activity, emails and other audit logs to identify the access route.
For businesses that hold lead databases, this scenario reinforces the need for least-privilege access, monitoring of large exports, data-loss prevention controls, and immutable logs.
There is no evidence that the allegedly exposed CARS24 data was used for financial fraud. However, details such as a customer’s name, telephone number, vehicle model, listing status and anticipated price can enable targeted social engineering.
A caller who already knows those details may seem trustworthy when asking for an OTP, an identity document, or a payment.
Customers who receive unexpected calls from dealers with detailed vehicle-listing information should ask how their data was sourced, avoid sharing OTPs or banking details, retain suspicious messages and report concerns to CARS24 and cybercrime authorities.
Police must now establish whether the 3,100 records were extracted, who allegedly transferred them, whether leads reached more dealers and whether the named individuals participated. Until the inquiry concludes, the allegations against the individuals and Direct-Cars remain unproven.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

