Gordon Freeman Claims Attack on Yummy Rides
On March 8, 2026, Yummy Rides suffered the unauthorized extraction of the full names and profile photos of approximately 30,000 drivers, exploiting an unpatched vulnerability. CEO Vicente Zavarce addressed the incident on X, describing it as a thwarted “attempt” and stating that no financial or sensitive user data was compromised. However, the actor GordonFreeman (attributed by VECERT) published the database of ~30,000 images linked to full names as a free download on the dark web, with screenshots as proof, and the NGO RedesAyuda (Luis Serrano) publicly refuted the company’s account, confirming that a data breach did occur.
Overview
Missing evidence
Impact details
30,000 Exposed records
30,000 Affected people
Yummy/Vicente Zavarce has confirmed a limited data breach affecting the names and profile photos of approximately 30,000 drivers, which was detected on March 8, 2026, and has since been resolved. Sources consulted do not confirm that financial data, identification documents, phone numbers, addresses, email addresses, passwords, travel data, or transaction data were exposed.
Classification & severity
- Category
- Information content security
- Subtype
- Leak of confidential information
- Confidence
- Medium
Severity assessment
Low- Functional impact
- None
- Information impact
- Personal data
- Affected scope
- Multiple users
- Critical service
- None
- Public confidence
- Limited
- Recoverability
- Regular
Official information and information provided by the company confirm limited exposure of the names and profile photos of approximately 30,000 drivers; no exposure of sensitive data related to financial status, identity, travel, or transactions has been confirmed.
Timeline
GordonFreeman reported the leak of approximately 30,000 images and driver names from Yummy Rides.