Cars24 alleges confidential records of around 3,100 customers were stolen and sold to rival dealers, causing an estimated ₹5.70 crore commercial loss.

Cars24 Alleges 3,100 Customer Records Stolen and Sold for ₹1,000 Per Lead

The420 Web Correspondent
7 Min Read

Used-car platform Cars24 has alleged that confidential information belonging to around 3,100 customers was stolen and passed to a rival business and outside dealers, causing an estimated commercial loss of ₹5.70 crore.

The case has been registered at the Cyber Crime Police Station following a complaint by Cars24 legal head Shyamal Anand. Five people — Preeti, Pallavi, Kalpana, Sahil Rana and Mohit — have been named in the FIR.

According to the complaint, customer and business information was allegedly taken between March and August and supplied to Punjab-based Direct-Cars.

Cars24 claims WhatsApp conversations obtained during its internal inquiry indicate that customer leads were being offered for around ₹1,000 each.

Police are now examining how the information left the company’s systems, who had access to it and whether the data was sold to additional dealers.

Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions

Names, Phone Numbers and Vehicle Reports Allegedly Leaked

The allegedly compromised information went considerably beyond a simple list of telephone numbers.

According to the complaint, it included customer names, mobile numbers, vehicle details, appointments, inspection reports, pricing information, sales leads and other internal business records.

That combination has substantial commercial value in the used-car industry.

A dealer who knows that a particular person is already trying to sell a specific vehicle does not need to spend money finding that customer. It can simply call the person directly and attempt to offer a better price.

Cars24 says this is effectively what happened.

The alleged leak reportedly came to the company’s attention after people associated with another business began contacting Cars24 customers.

The company subsequently examined communications and alleges that WhatsApp conversations revealed how customer leads were being distributed.

The ₹5.70 crore figure represents Cars24’s estimate of the business it believes was lost because of the alleged diversion. Police have not independently established that amount.

What Is a Customer Lead and Why Would Anyone Pay ₹1,000 for It?

A customer lead is information identifying someone who is already interested in buying or selling something.

For a used-car company, a lead might contain a person’s phone number, car model, expected price and an appointment for inspection.

That information is more valuable than a random phone number.

Imagine two dealers trying to find someone planning to sell a car. One must advertise, call hundreds of people and wait for responses. The other receives a spreadsheet containing people who have already requested vehicle inspections.

The second dealer has effectively jumped to the front of the queue.

This explains why companies treat lead databases as confidential commercial information.

The case also highlights the difference between a data breach and an external hacking attack.

A breach simply means protected information has been accessed, copied, disclosed or lost without authorisation. It does not automatically mean hackers broke through a firewall.

An employee or contractor who legitimately has access to customer records but secretly copies and sells them can also create a serious data breach.

Police have not yet disclosed which route was allegedly used in the Cars24 case.

A Similar Case Recently Reached Maharashtra’s IT Adjudicating Officer

The allegations closely resemble another recent corporate data-theft dispute.

In July, Maharashtra’s IT Adjudicating Officer granted an interim injunction in a case brought by Cordelia Cruises after the company alleged that an employee copied confidential customer leads and diverted them to competing businesses.

A forensic audit in that case allegedly found unauthorised extraction of prospective customer records. Cordelia claimed the diverted leads caused about ₹66 lakh in revenue loss. The adjudicating officer restrained the respondents from using or distributing the proprietary customer database while the dispute continued.

That case illustrates why a customer database can be treated simultaneously as personal information and a valuable corporate asset.

Police investigations into data markets have also repeatedly found customer information being sold to fraud networks.

Noida cybercrime officials told The Times of India last year that insiders at banks, NBFCs and outsourced call centres were among the channels through which customer leads entered illegal data markets. Such records could later be used for targeted financial scams because criminals already knew details about the victim.

There is no evidence at this stage that the Cars24 records were used for financial fraud. The allegation is that they were exploited commercially to divert customers.

Police Must Now Find the Original Access Point

The most important unanswered question is how 3,100 records were allegedly obtained.

Investigators can examine login histories, downloads, device records, email activity and other system logs to determine whether information was exported through an authorised account or accessed through compromised credentials.

WhatsApp messages and financial transactions could then help establish who received the records and whether money changed hands.

The investigation also arrives as India strengthens its personal-data regime.

The Digital Personal Data Protection Act requires organisations handling personal information to take reasonable safeguards against breaches. The legislation provides for penalties reaching ₹250 crore for failure to meet certain security obligations, although implementation of different provisions has followed a phased timetable.

Cars24 describes itself as an auto-ownership platform connecting buyers, sellers, dealers, financing partners and vehicle information. Its own disclosures say the platform handles more than five lakh data points each month for vehicle assessment and pricing.

That scale makes access controls especially important.

For police, the immediate task is narrower: establish whether the records were actually stolen, how they were extracted, who sold them and whether the five people named in the FIR participated in the alleged operation.

Until that investigation is completed, the allegations against the named individuals and Direct-Cars remain unproven.

What this means for you: If a dealer unexpectedly knows detailed information about a car you listed with another platform, ask where it obtained your details and report suspicious contact to the original company. Avoid sharing OTPs, identity documents or additional financial information merely because the caller already knows your name and vehicle details.

https://www.linkedin.com/company/policetechnology/

Stay Connected