Company Details
europcar-mobility-group
7,877
81,308
5615
europcar-mobility-group.com
0
EUR_1637813
In-progress

Europcar Mobility Group Company CyberSecurity Posture
europcar-mobility-group.comEuropcar Mobility Group is a global mobility player, with 75 years of mobility services expertise and a leading position in Europe. “We help to change the way you move” is what we stand for and brings us together. More than ever, we're committed to delivering simple, seamless, innovative solutions that make mobility easy, enjoyable and increasingly eco-friendly. To do this, we offer to individuals and businesses a wide range of car and van rental services, be it for a few hours, a few days, a week, a month or more, on-demand or on subscription, relying on a fleet of more than 250.000 vehicles, equipped with the latest engines including an increasing share of electric vehicles. Our brands address differentiated needs, use cases and expectations: Europcar® - a global leader of car rental and light commercial vehicle rental, Goldcar® - a frontrunner at providing low-cost car rental services in Europe, and Fox Rent A Car®, one of the main players in the car rental market in the US, with a "value for money" positioning. The Group also operates the "myEuropcar" platform for vehicle subscription, and "Europcar on Demand", a roundtrip car-sharing service present in key cities in Europe. Customers’ satisfaction is at the heart of the Group’s ambition and that of our more than 8,000 employees, everywhere we deliver our mobility solutions, thanks to a strong network in over 130 countries (including 16 wholly owned subsidiaries completed by franchisees and alliance partners).
Company Details
europcar-mobility-group
7,877
81,308
5615
europcar-mobility-group.com
0
EUR_1637813
In-progress
Between 700 and 749

EMG Global Score (TPRM)XXXX

Description: A hacker accessed the GitLab repositories of Europcar Mobility Group, compromising source code for mobile applications and personal information of up to 200,000 customers. The breach included 37GB of data such as backups, details about cloud infrastructure, and internal apps. While credit card information and passwords were not exposed, the loss of personal data such as names and email addresses constitutes a significant privacy concern for customers of the diverse range of Europcar, Goldcar, and Ubeeqo brands operating across 140 countries.


Europcar Mobility Group has 20.48% more incidents than the average of same-industry companies with at least one recorded incident.
Europcar Mobility Group has 56.25% more incidents than the average of all companies with at least one recorded incident.
Europcar Mobility Group reported 1 incidents this year: 0 cyber attacks, 0 ransomware, 0 vulnerabilities, 1 data breaches, compared to industry peers with at least 1 incident.
EMG cyber incidents detection timeline including parent company and subsidiaries

Europcar Mobility Group is a global mobility player, with 75 years of mobility services expertise and a leading position in Europe. “We help to change the way you move” is what we stand for and brings us together. More than ever, we're committed to delivering simple, seamless, innovative solutions that make mobility easy, enjoyable and increasingly eco-friendly. To do this, we offer to individuals and businesses a wide range of car and van rental services, be it for a few hours, a few days, a week, a month or more, on-demand or on subscription, relying on a fleet of more than 250.000 vehicles, equipped with the latest engines including an increasing share of electric vehicles. Our brands address differentiated needs, use cases and expectations: Europcar® - a global leader of car rental and light commercial vehicle rental, Goldcar® - a frontrunner at providing low-cost car rental services in Europe, and Fox Rent A Car®, one of the main players in the car rental market in the US, with a "value for money" positioning. The Group also operates the "myEuropcar" platform for vehicle subscription, and "Europcar on Demand", a roundtrip car-sharing service present in key cities in Europe. Customers’ satisfaction is at the heart of the Group’s ambition and that of our more than 8,000 employees, everywhere we deliver our mobility solutions, thanks to a strong network in over 130 countries (including 16 wholly owned subsidiaries completed by franchisees and alliance partners).


Norwegian Cruise Line Holdings Ltd. (NYSE: NCLH) is a leading global cruise company which operates Norwegian Cruise Line, Oceania Cruises and Regent Seven Seas Cruises. With a combined fleet of 32 ships and approximately 66,500 berths, NCLH offers itineraries to approximately 700 destinations worl

Headquartered in Geneva, Switzerland, MSC Cruises is the world’s third largest cruise lines and the market leader in Europe, South America, the Middle East and Southern Africa, with a strong and growing presence in North America and the Far East. The MSC Cruises fleet consists of 22 modern ships wi

CWT is a global business travel and meetings specialist, with whom companies and governments partner to keep their people connected, in traditional business locations and some of the most remote and inaccessible parts of the globe. A private company – owned through funds managed by a group of leadin
Since our founding in 1972, Carnival Cruise Line — "The World’s Most Popular Cruise Line®” — carries millions of passengers every year. We offer a fun and unique career destination for a wide range of professionals in Marketing, IT, Accounting/Audit, Finance, Marine Operations and Human Resources, j

Hertz is one of the world’s largest mobility companies, and through its indirect subsidiary, The Hertz Corporation, operates the Hertz, Dollar, and Thrifty vehicle rental brands throughout North America, Europe, the Caribbean, Latin America, Africa, the Middle East, Asia, Australia, and New Zealand.

Princess is the world’s leading premium cruise line operating a fleet of modern ships visiting over 380 destinations around the globe on more than 160 itineraries. Each moment on Princess is one of wonderful discovery where guests can relax and explore. The choices are endless, from invigorating act

DER TOURISTIK GROUP AUF WACHSTUMSKURS Die DER Touristik Group gehört heute zu den führenden europäischen Reisekonzernen. Sie vereint unter ihrem Dach verschiedene Geschäftsfelder rund ums Thema Reisen und agiert seit 2018 strukturell als Holding mit vier Divisions. Durch den Zukauf der europäische

BCD Travel helps companies travel smart and achieve more. We drive program adoption, cost savings and talent retention through digital experiences that simplify business travel. Our 15,000+ dedicated team members service clients in 170+ countries as we shape a sustainable future for business travel.
At Royal Caribbean Group, we deliver unforgettable vacations to guests who trust us with life’s greatest moments. We build the best ships, and even better careers, all while doing the right thing. We are passionate. We are innovative. We are unstoppable. We open the world to our employees. Your jour
.png)
PRNewswire/ -- Europcar Mobility Group is a leader in global mobility services leader with more than 75 years of expertise.
A hacker breached Europcar's GitLab repositories, stealing mobile app source code and personal data linked to up to 200000 customers.
A hacker gained access to the GitLab repositories of the Europcar Mobility Group car rental company. The hack resulted in the theft of the...
Latest Research by our Team.
As many as 200000 customers of the Europcar Mobility Group (Europcar) have had their data compromised after threat actors breached the...
A hacker breached the GitLab repositories of multinational car-rental company Europcar Mobility Group and stole source code for Android and iOS applications.
PARIS--(BUSINESS WIRE)--Europcar Mobility Group pushes forward its ambition to connect all the vehicles in its fleet by the end of 2024 and,...
The partnership will help Satguru Travel accelerate its growth establishing the Europcar brand as a Premium mobility solution in India.
Green Mobility Holding, a bidder consortium led by Volkswagen Group, has acquired 87.38% shares in French car rental group Europcar.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Europcar Mobility Group is http://www.europcar-mobility-group.com.
According to Rankiteo, Europcar Mobility Group’s AI-generated cybersecurity score is 706, reflecting their Moderate security posture.
According to Rankiteo, Europcar Mobility Group currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Europcar Mobility Group is not certified under SOC 2 Type 1.
According to Rankiteo, Europcar Mobility Group does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Europcar Mobility Group is not listed as GDPR compliant.
According to Rankiteo, Europcar Mobility Group does not currently maintain PCI DSS compliance.
According to Rankiteo, Europcar Mobility Group is not compliant with HIPAA regulations.
According to Rankiteo,Europcar Mobility Group is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Europcar Mobility Group operates primarily in the Travel Arrangements industry.
Europcar Mobility Group employs approximately 7,877 people worldwide.
Europcar Mobility Group presently has no subsidiaries across any sectors.
Europcar Mobility Group’s official LinkedIn profile has approximately 81,308 followers.
Europcar Mobility Group is classified under the NAICS code 5615, which corresponds to Travel Arrangement and Reservation Services.
No, Europcar Mobility Group does not have a profile on Crunchbase.
Yes, Europcar Mobility Group maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/europcar-mobility-group.
As of November 29, 2025, Rankiteo reports that Europcar Mobility Group has experienced 1 cybersecurity incidents.
Europcar Mobility Group has an estimated 4,752 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Title: Europcar Mobility Group Data Breach
Description: A hacker accessed the GitLab repositories of Europcar Mobility Group, compromising source code for mobile applications and personal information of up to 200,000 customers. The breach included 37GB of data such as backups, details about cloud infrastructure, and internal apps. While credit card information and passwords were not exposed, the loss of personal data such as names and email addresses constitutes a significant privacy concern for customers of the diverse range of Europcar, Goldcar, and Ubeeqo brands operating across 140 countries.
Type: Data Breach
Attack Vector: Unauthorized Access to GitLab Repositories
Threat Actor: Hacker
Common Attack Types: The most common types of attacks the company has faced is Breach.
Identification of Attack Vectors: The company identifies the attack vectors used in incidents through GitLab repositories.

Data Compromised: 37GB of data including source code, backups, details about cloud infrastructure, internal apps, and personal information
Systems Affected: GitLab repositories
Brand Reputation Impact: Significant privacy concern
Identity Theft Risk: High
Payment Information Risk: Low
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Source Code For Mobile Applications, Personal Information, Backups, Details About Cloud Infrastructure, Internal Apps and .

Entity Name: Europcar Mobility Group
Entity Type: Company
Industry: Car Rental
Location: Operating across 140 countries
Customers Affected: 200000

Type of Data Compromised: Source code for mobile applications, Personal information, Backups, Details about cloud infrastructure, Internal apps
Number of Records Exposed: 200000
Sensitivity of Data: High
Personally Identifiable Information: NamesEmail addresses

Entry Point: GitLab repositories
Last Attacking Group: The attacking group in the last incident was an Hacker.
Most Significant Data Compromised: The most significant data compromised in an incident were 37GB of data including source code, backups, details about cloud infrastructure, internal apps and and personal information.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were 37GB of data including source code, backups, details about cloud infrastructure, internal apps and and personal information.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 200.0.
Most Recent Entry Point: The most recent entry point used by an initial access broker was an GitLab repositories.
.png)
ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images are embedded in an `iframe` element, during a widget creation, deployed to any page of the platform (e.g., dashboards), and accessed during normal operations. The vulnerability resides in the `ImageController`, which fails to restrict the execution of JavaScript code when an image is loaded by the user's browser. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint
Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.
Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.