Car-sharing and mobility platform operating in the Baltics.
In February 2021, the Lithuanian car-sharing service CityBee suffered a data breach exposing about 110,000 customers. Exposed data included names, email addresses, government-issued ID numbers, and passwords stored as unsalted SHA-1 hashes. CityBee was later ordered to pay damages over the incident.
ObscureIQ assessment: High risk of identity fraud, account takeover, and physical tracking. Location and usage data increase real-world targeting exposure.
Government-ID numbers alongside identity data raise identity-fraud risk beyond credentials; unsalted SHA-1 passwords are readily cracked.
CityBee is a Lithuanian car-sharing service.
Car-sharing platforms collect user identity, driver credentials, payment data, and usage logs tied to short-term vehicle access and location tracking.
Field names are shown in full for clarity and search visibility. Canonical machine keys are emitted only in this page’s structured data.
If you believe your information may be included:
In February 2021, the Lithuanian car-sharing service CityBee suffered a data breach exposing about 110,000 customers. Exposed data included names, email addresses, government-issued ID numbers, and passwords stored as unsalted SHA-1 hashes. CityBee was later ordered to pay damages over the incident.
Verified fields include Email Address, Full Name, Government ID, Password.
Change reused passwords, enable MFA, and (if identity or financial data is involved) freeze your credit and monitor your accounts.
Every claim on this page is traceable. This breach draws on:
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation