ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Europcar Mobility Group is a global mobility player, with 75 years of mobility services expertise and a leading position in Europe. “We help to change the way you move” is what we stand for and brings us together. More than ever, we're committed to delivering simple, seamless, innovative solutions that make mobility easy, enjoyable and increasingly eco-friendly. To do this, we offer to individuals and businesses a wide range of car and van rental services, be it for a few hours, a few days, a week, a month or more, on-demand or on subscription, relying on a fleet of more than 250.000 vehicles, equipped with the latest engines including an increasing share of electric vehicles. Our brands address differentiated needs, use cases and expectations: Europcar® - a global leader of car rental and light commercial vehicle rental, Goldcar® - a frontrunner at providing low-cost car rental services in Europe, and Fox Rent A Car®, one of the main players in the car rental market in the US, with a "value for money" positioning. The Group also operates the "myEuropcar" platform for vehicle subscription, and "Europcar on Demand", a roundtrip car-sharing service present in key cities in Europe. Customers’ satisfaction is at the heart of the Group’s ambition and that of our more than 8,000 employees, everywhere we deliver our mobility solutions, thanks to a strong network in over 130 countries (including 16 wholly owned subsidiaries completed by franchisees and alliance partners).

Europcar Mobility Group A.I CyberSecurity Scoring

EMG

Company Details

Linkedin ID:

europcar-mobility-group

Employees number:

7,877

Number of followers:

81,308

NAICS:

5615

Industry Type:

Travel Arrangements

Homepage:

europcar-mobility-group.com

IP Addresses:

0

Company ID:

EUR_1637813

Scan Status:

In-progress

AI scoreEMG Risk Score (AI oriented)

Between 700 and 749

https://images.rankiteo.com/companyimages/europcar-mobility-group.jpeg
EMG Travel Arrangements
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreEMG Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/europcar-mobility-group.jpeg
EMG Travel Arrangements
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

EMG Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Europcar Mobility GroupBreach8544/2025
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: A hacker accessed the GitLab repositories of Europcar Mobility Group, compromising source code for mobile applications and personal information of up to 200,000 customers. The breach included 37GB of data such as backups, details about cloud infrastructure, and internal apps. While credit card information and passwords were not exposed, the loss of personal data such as names and email addresses constitutes a significant privacy concern for customers of the diverse range of Europcar, Goldcar, and Ubeeqo brands operating across 140 countries.

Europcar Mobility Group
Breach
Severity: 85
Impact: 4
Seen: 4/2025
Blog:
Rankiteo Explanation
Attack with significant impact with customers data leaks

Description: A hacker accessed the GitLab repositories of Europcar Mobility Group, compromising source code for mobile applications and personal information of up to 200,000 customers. The breach included 37GB of data such as backups, details about cloud infrastructure, and internal apps. While credit card information and passwords were not exposed, the loss of personal data such as names and email addresses constitutes a significant privacy concern for customers of the diverse range of Europcar, Goldcar, and Ubeeqo brands operating across 140 countries.

Ailogo

EMG Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for EMG

Incidents vs Travel Arrangements Industry Average (This Year)

Europcar Mobility Group has 20.48% more incidents than the average of same-industry companies with at least one recorded incident.

Incidents vs All-Companies Average (This Year)

Europcar Mobility Group has 56.25% more incidents than the average of all companies with at least one recorded incident.

Incident Types EMG vs Travel Arrangements Industry Avg (This Year)

Europcar Mobility Group reported 1 incidents this year: 0 cyber attacks, 0 ransomware, 0 vulnerabilities, 1 data breaches, compared to industry peers with at least 1 incident.

Incident History — EMG (X = Date, Y = Severity)

EMG cyber incidents detection timeline including parent company and subsidiaries

EMG Company Subsidiaries

SubsidiaryImage

Europcar Mobility Group is a global mobility player, with 75 years of mobility services expertise and a leading position in Europe. “We help to change the way you move” is what we stand for and brings us together. More than ever, we're committed to delivering simple, seamless, innovative solutions that make mobility easy, enjoyable and increasingly eco-friendly. To do this, we offer to individuals and businesses a wide range of car and van rental services, be it for a few hours, a few days, a week, a month or more, on-demand or on subscription, relying on a fleet of more than 250.000 vehicles, equipped with the latest engines including an increasing share of electric vehicles. Our brands address differentiated needs, use cases and expectations: Europcar® - a global leader of car rental and light commercial vehicle rental, Goldcar® - a frontrunner at providing low-cost car rental services in Europe, and Fox Rent A Car®, one of the main players in the car rental market in the US, with a "value for money" positioning. The Group also operates the "myEuropcar" platform for vehicle subscription, and "Europcar on Demand", a roundtrip car-sharing service present in key cities in Europe. Customers’ satisfaction is at the heart of the Group’s ambition and that of our more than 8,000 employees, everywhere we deliver our mobility solutions, thanks to a strong network in over 130 countries (including 16 wholly owned subsidiaries completed by franchisees and alliance partners).

Loading...
similarCompanies

EMG Similar Companies

Norwegian Cruise Line Holdings Ltd.

Norwegian Cruise Line Holdings Ltd. (NYSE: NCLH) is a leading global cruise company which operates Norwegian Cruise Line, Oceania Cruises and Regent Seven Seas Cruises. With a combined fleet of 32 ships and approximately 66,500 berths, NCLH offers itineraries to approximately 700 destinations worl

MSC Cruises

Headquartered in Geneva, Switzerland, MSC Cruises is the world’s third largest cruise lines and the market leader in Europe, South America, the Middle East and Southern Africa, with a strong and growing presence in North America and the Far East. The MSC Cruises fleet consists of 22 modern ships wi

CWT is a global business travel and meetings specialist, with whom companies and governments partner to keep their people connected, in traditional business locations and some of the most remote and inaccessible parts of the globe. A private company – owned through funds managed by a group of leadin

Carnival Cruise Line

Since our founding in 1972, Carnival Cruise Line — "The World’s Most Popular Cruise Line®” — carries millions of passengers every year. We offer a fun and unique career destination for a wide range of professionals in Marketing, IT, Accounting/Audit, Finance, Marine Operations and Human Resources, j

Hertz

Hertz is one of the world’s largest mobility companies, and through its indirect subsidiary, The Hertz Corporation, operates the Hertz, Dollar, and Thrifty vehicle rental brands throughout North America, Europe, the Caribbean, Latin America, Africa, the Middle East, Asia, Australia, and New Zealand.

Princess Cruises

Princess is the world’s leading premium cruise line operating a fleet of modern ships visiting over 380 destinations around the globe on more than 160 itineraries. Each moment on Princess is one of wonderful discovery where guests can relax and explore. The choices are endless, from invigorating act

DER Touristik vormals REWE Touristik GmbH

DER TOURISTIK GROUP AUF WACHSTUMSKURS Die DER Touristik Group gehört heute zu den führenden europäischen Reisekonzernen. Sie vereint unter ihrem Dach verschiedene Geschäftsfelder rund ums Thema Reisen und agiert seit 2018 strukturell als Holding mit vier Divisions. Durch den Zukauf der europäische

BCD Travel

BCD Travel helps companies travel smart and achieve more. We drive program adoption, cost savings and talent retention through digital experiences that simplify business travel. Our 15,000+ dedicated team members service clients in 170+ countries as we shape a sustainable future for business travel.

Royal Caribbean Group

At Royal Caribbean Group, we deliver unforgettable vacations to guests who trust us with life’s greatest moments. We build the best ships, and even better careers, all while doing the right thing. We are passionate. We are innovative. We are unstoppable. We open the world to our employees. Your jour

newsone

EMG CyberSecurity News

July 28, 2025 07:00 AM
Europcar Mobility Group Chooses OpenText to Deliver Global E-Invoicing Compliance

PRNewswire/ -- Europcar Mobility Group is a leader in global mobility services leader with more than 75 years of expertise.

July 09, 2025 10:06 AM
Up to 200,000 Europcar users affected in GitLab security breach

A hacker breached Europcar's GitLab repositories, stealing mobile app source code and personal data linked to up to 200000 customers.

April 07, 2025 07:00 AM
Data breach at Europcar: GitLab hack affects up to 200,000 customers

A hacker gained access to the GitLab repositories of the Europcar Mobility Group car rental company. The hack resulted in the theft of the...

April 07, 2025 07:00 AM
7th April – Threat Intelligence Report

Latest Research by our Team.

April 07, 2025 07:00 AM
As many as 200k affected in Europcar data incident

As many as 200000 customers of the Europcar Mobility Group (Europcar) have had their data compromised after threat actors breached the...

April 04, 2025 07:00 AM
Europcar GitLab breach exposes data of up to 200,000 customers

A hacker breached the GitLab repositories of multinational car-rental company Europcar Mobility Group and stole source code for Android and iOS applications.

March 13, 2024 07:00 AM
Europcar Mobility Group Reaches New Key Milestones in its “Connected Vehicles” program:

PARIS--(BUSINESS WIRE)--Europcar Mobility Group pushes forward its ambition to connect all the vehicles in its fleet by the end of 2024 and,...

March 04, 2024 08:00 AM
Europcar Mobility Group expands in India

The partnership will help Satguru Travel accelerate its growth establishing the Europcar brand as a Premium mobility solution in India.

June 16, 2022 07:00 AM
Volkswagen-led Green Mobility takes 87% stake in Europcar Mobility Group

Green Mobility Holding, a bidder consortium led by Volkswagen Group, has acquired 87.38% shares in French car rental group Europcar.

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

EMG CyberSecurity History Information

Official Website of Europcar Mobility Group

The official website of Europcar Mobility Group is http://www.europcar-mobility-group.com.

Europcar Mobility Group’s AI-Generated Cybersecurity Score

According to Rankiteo, Europcar Mobility Group’s AI-generated cybersecurity score is 706, reflecting their Moderate security posture.

How many security badges does Europcar Mobility Group’ have ?

According to Rankiteo, Europcar Mobility Group currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Europcar Mobility Group have SOC 2 Type 1 certification ?

According to Rankiteo, Europcar Mobility Group is not certified under SOC 2 Type 1.

Does Europcar Mobility Group have SOC 2 Type 2 certification ?

According to Rankiteo, Europcar Mobility Group does not hold a SOC 2 Type 2 certification.

Does Europcar Mobility Group comply with GDPR ?

According to Rankiteo, Europcar Mobility Group is not listed as GDPR compliant.

Does Europcar Mobility Group have PCI DSS certification ?

According to Rankiteo, Europcar Mobility Group does not currently maintain PCI DSS compliance.

Does Europcar Mobility Group comply with HIPAA ?

According to Rankiteo, Europcar Mobility Group is not compliant with HIPAA regulations.

Does Europcar Mobility Group have ISO 27001 certification ?

According to Rankiteo,Europcar Mobility Group is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Europcar Mobility Group

Europcar Mobility Group operates primarily in the Travel Arrangements industry.

Number of Employees at Europcar Mobility Group

Europcar Mobility Group employs approximately 7,877 people worldwide.

Subsidiaries Owned by Europcar Mobility Group

Europcar Mobility Group presently has no subsidiaries across any sectors.

Europcar Mobility Group’s LinkedIn Followers

Europcar Mobility Group’s official LinkedIn profile has approximately 81,308 followers.

NAICS Classification of Europcar Mobility Group

Europcar Mobility Group is classified under the NAICS code 5615, which corresponds to Travel Arrangement and Reservation Services.

Europcar Mobility Group’s Presence on Crunchbase

No, Europcar Mobility Group does not have a profile on Crunchbase.

Europcar Mobility Group’s Presence on LinkedIn

Yes, Europcar Mobility Group maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/europcar-mobility-group.

Cybersecurity Incidents Involving Europcar Mobility Group

As of November 29, 2025, Rankiteo reports that Europcar Mobility Group has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

Europcar Mobility Group has an estimated 4,752 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Europcar Mobility Group ?

Incident Types: The types of cybersecurity incidents that have occurred include Breach.

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: Europcar Mobility Group Data Breach

Description: A hacker accessed the GitLab repositories of Europcar Mobility Group, compromising source code for mobile applications and personal information of up to 200,000 customers. The breach included 37GB of data such as backups, details about cloud infrastructure, and internal apps. While credit card information and passwords were not exposed, the loss of personal data such as names and email addresses constitutes a significant privacy concern for customers of the diverse range of Europcar, Goldcar, and Ubeeqo brands operating across 140 countries.

Type: Data Breach

Attack Vector: Unauthorized Access to GitLab Repositories

Threat Actor: Hacker

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Breach.

How does the company identify the attack vectors used in incidents ?

Identification of Attack Vectors: The company identifies the attack vectors used in incidents through GitLab repositories.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach EUR531040425

Data Compromised: 37GB of data including source code, backups, details about cloud infrastructure, internal apps, and personal information

Systems Affected: GitLab repositories

Brand Reputation Impact: Significant privacy concern

Identity Theft Risk: High

Payment Information Risk: Low

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Source Code For Mobile Applications, Personal Information, Backups, Details About Cloud Infrastructure, Internal Apps and .

Which entities were affected by each incident ?

Incident : Data Breach EUR531040425

Entity Name: Europcar Mobility Group

Entity Type: Company

Industry: Car Rental

Location: Operating across 140 countries

Customers Affected: 200000

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach EUR531040425

Type of Data Compromised: Source code for mobile applications, Personal information, Backups, Details about cloud infrastructure, Internal apps

Number of Records Exposed: 200000

Sensitivity of Data: High

Personally Identifiable Information: NamesEmail addresses

Initial Access Broker

How did the initial access broker gain entry for each incident ?

Incident : Data Breach EUR531040425

Entry Point: GitLab repositories

Additional Questions

General Information

Who was the attacking group in the last incident ?

Last Attacking Group: The attacking group in the last incident was an Hacker.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were 37GB of data including source code, backups, details about cloud infrastructure, internal apps and and personal information.

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were 37GB of data including source code, backups, details about cloud infrastructure, internal apps and and personal information.

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 200.0.

Initial Access Broker

What was the most recent entry point used by an initial access broker ?

Most Recent Entry Point: The most recent entry point used by an initial access broker was an GitLab repositories.

cve

Latest Global CVEs (Not Company-Specific)

Description

ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images are embedded in an `iframe` element, during a widget creation, deployed to any page of the platform (e.g., dashboards), and accessed during normal operations. The vulnerability resides in the `ImageController`, which fails to restrict the execution of JavaScript code when an image is loaded by the user's browser. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.

Risk Information
cvss4
Base: 6.2
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).

Risk Information
cvss3
Base: 9.9
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint

Risk Information
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description

Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.

Description

Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=europcar-mobility-group' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge