LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Dunzo Data Breach (2020)

HIGH severityConfirmedHow we verify

Dunzo Data Breach (2020): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 19, 2020

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Dunzo Data Breach (2020)

Reported June 19, 2020. Approximately 3.5M people affected.

HIGH
Severity
3.5M
People affected
6
Data types exposed
June 19, 2020
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Dunzo Data Breach (2020) (reported June 19, 2020) exposed Device information, Email addresses, Geographic locations and IP addresses belonging to roughly 3.5M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Dunzo Data Breach (2020) breach?
3.5M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Data breaches continue to affect organisations that hold large volumes of customer contact and location data. In June 2020, records from a breach at the Indian delivery service Dunzo were reported to have reached public breach-notification sites. The incident involved approximately 3.5 million records and drew attention because the data appeared on a hacking forum roughly one year earlier.

What happened

According to the available records, the Dunzo incident occurred around June 2019. On 19 June 2020 the breach was added to Have I Been Pwned after the data set was supplied by dehashed.com. The material had already been posted on a hacking forum and contained 3.5 million unique email addresses along with associated fields.

Public reporting does not include a technical description of how the data left Dunzo’s systems. The scale of the exposure, the date of the original compromise, and the types of information listed are the only Reported Details at present.

How a breach like this happens

Incidents that result in customer records appearing on forums often begin with unauthorised access to an organisation’s database or backup storage. Attackers may exploit an unpatched server, obtain valid credentials, or use other entry points that allow them to copy files without immediate detection.

Once data is removed, it can be shared or sold on closed forums. The presence of the Dunzo records on such a forum indicates that the material circulated beyond the initial point of access, though the exact sequence of events remains undisclosed.

Dunzo and its sector

Dunzo operates a delivery platform in India that connects customers with local stores and couriers. Services of this type routinely collect names, contact details, device identifiers and location information to arrange pick-ups and deliveries.

Because these platforms process orders in real time, they accumulate data sets that include both persistent identifiers and transient location records. A breach at one such service therefore exposes information that can be linked across multiple accounts or services.

What was likely exposed

The records reported in connection with the Dunzo breach include device information, email addresses, geographic locations, IP addresses, names and phone numbers. These categories match the types of data a delivery service would normally store to fulfil orders.

Whether every record contained all listed fields, or whether additional categories were present, has not been confirmed in public statements. The precise contents of the data set therefore remain unverified beyond the fields already noted.

The real-world impact

Individuals whose details appeared in the data set may receive unsolicited messages or see their contact information used in attempts to gain access to other accounts. Phone numbers and email addresses are frequently reused across services, which can extend the reach of any follow-on activity.

For the organisation, the incident adds to the body of known exposures affecting delivery platforms. It does not, on its own, demonstrate systemic failure, but it illustrates the consequences when large volumes of customer data are obtained and circulated.

Were you affected?

Anyone who used Dunzo before mid-2019 can check whether their email address appears in the reported data set by using a free exposure scan offered by Have I Been Pwned or similar services. Changing passwords on Dunzo and any other accounts that share the same email or phone number is a prudent first step.

Monitoring for unusual account activity and enabling multi-factor authentication on services that support it can reduce the chance that exposed contact details are used successfully. No further official notification process has been described in the available reporting.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyDunzo security record
74/100
DoxxScan™ · Moderate doxx risk
B- 78Above-average record

1 reported incident on record.

See Dunzo’s full breach history →

More recent breaches

University of California Data Breach (2020)December 24, 2020Roblox Developer Conference (2023) Data Breach (2020)December 18, 2020Travel Oklahoma Data Breach (2020)December 17, 2020Capital Economics Data Breach (2020)December 12, 2020

Latest breaches

Read GalaxyWarden’s full analysis of the Dunzo Data Breach (2020) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram