EasyPark Group discovered a cyberattack on December 10, 2023. It said some customers’ contact details and partial payment information were accessed, and hashed passwords were accessed for some customers who received a breach notification. EasyPark did not publish a final total number of affected people; it identified 950 UK RingGo users and said most affected customers used EasyPark elsewhere in Europe.
EasyPark said the exposed information could not be used to make payments and that parking data was not compromised. Those are the company’s assessments. For customers, the practical concerns are targeted phishing and any password reused on other services.
What happened in the 2023 EasyPark breach?
EasyPark Group said it discovered unauthorized access to its systems on December 10, 2023, and published its initial customer notice on December 14. The company said it took steps to stop the attack, reset affected customers’ passwords, notified regulators, and contacted people it believed were affected. EasyPark’s notice and FAQ describe the incident and its response.
Unauthorized access means someone entered or viewed systems without permission; it does not by itself establish that every record was copied, published, or misused. EasyPark said at the time that it had no knowledge of data being published or used and had received no ransom demand. That is the company’s account at that point, not proof that misuse could never occur.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors#1 Best Overall
In April 2024, EasyPark said Dutch criminal proceedings related to the incident were ongoing and that it was assisting police and prosecutors. The public material cited here does not establish a final court outcome or a complete account of the attack method. EasyPark’s April 2024 update addresses the proceedings.
How many people were affected?
EasyPark did not disclose a confirmed overall victim count in the sources available. The company identified 950 affected RingGo users in the UK and said most affected customers were European users of the EasyPark brand. “Thousands” describes the reported scale, but it is not a published final count. The Guardian’s December 2023 report gives the RingGo figure and the company’s explanation of the wider impact.
What information may have been exposed?
The information varied by customer; the notice does not mean every affected person had every listed field accessed.
Rank #2
| Information | What EasyPark said |
|---|---|
| Name, phone number, physical address, and email address | Some contact information may have been accessed; fields varied by customer. |
| Partial debit-card, credit-card, or IBAN digits | Partial details were accessed for some customers, not complete payment credentials. |
| Hashed self-service-portal password | Accessed in cases where customers received a related email, SMS, or push notification. EasyPark said it reset affected customers’ passwords. |
| Parking data | EasyPark said it was not compromised. |
These descriptions are based on EasyPark’s account. The company’s characterization of the information as non-sensitive should not be read as a guarantee that it has no value to scammers.
What does “hashed password” mean?
A password hash is a one-way representation used to verify a password without storing the password itself in readable form. It is different from encryption, which is designed to be reversed with a key. A strong, properly configured hash is harder to recover, but the exact algorithm and configuration used in this incident were not stated in the sources cited here. Weak passwords and passwords reused on other sites remain a risk if a hash is exposed.
Could the exposed details be used to take money?
EasyPark said the partial card or IBAN details, alone or combined with the other accessed information, could not be used to make payments. This is the company’s assessment, not an independently established guarantee about every possible form of fraud.
Incomplete payment details can still make a scam more convincing when paired with a real name, address, phone number, or email. A message that refers to a parking account or partial payment reference may sound credible without being legitimate. The more immediate practical concern is therefore impersonation and phishing, while customers should still watch for unfamiliar transactions or account activity.
What should affected customers do?
- Verify messages independently. Do not click links in unexpected emails or texts. Open the EasyPark or RingGo app yourself, or type the company’s known web address into your browser. EasyPark warned about fraudulent emails claiming there was an unpaid parking bill; it said it does not send emails containing a direct payment link. See the company notice.
- Change reused passwords. EasyPark said affected passwords were reset. If you used the same password on email, banking, shopping, social-media, or any other account, change it on those services too. Use a distinct password for each account.
- Turn on multifactor authentication where available. Prioritize your email account, financial services, and password manager. MFA cannot undo exposure, but it can make account takeover harder.
- Monitor accounts and statements. Look for unfamiliar parking charges, password-reset messages, login alerts, and unexpected direct-debit activity. If you see suspicious financial activity, contact your bank or card issuer using the number on your card or its official app.
- Be cautious with targeted requests. Never provide a full card number, security code, password, one-time code, or identity-document details in response to an unsolicited message or call. A scammer may already know some of your contact information.
- Contact support through an official route. Use the app or the company’s official support site, not contact details supplied in a suspicious email or text.
Which brands and regions were involved?
EasyPark Group operates several parking brands, including EasyPark, RingGo, ParkMobile, and Park-line. The 2023 incident primarily concerned European EasyPark customers, with 950 RingGo users in the UK specifically identified. EasyPark said RingGo users were affected through services integrated with EasyPark technology, while the RingGo platform itself was not breached. It also said the ParkMobile brand in the United States was not affected by this 2023 incident. These distinctions are reported in The Guardian’s coverage and EasyPark’s notice.
Recommended Free Tools
“Europe’s largest parking app” is a description of EasyPark Group’s market position, not a universal ranking by a single measure such as active users, revenue, or transactions. The Guardian reported the group’s claim that its services operated in more than 4,000 cities across 23 countries.
Is this the same as the 2021 ParkMobile breach?
No. The December 2023 EasyPark Group incident and ParkMobile’s March 2021 U.S. incident were separate events with different reported data and geographies.
| December 2023 EasyPark Group incident | March 2021 ParkMobile incident | |
|---|---|---|
| Primary geography | Primarily Europe | United States |
| Brands and users | EasyPark customers and some RingGo users; 950 UK RingGo users identified | ParkMobile and related white-label app users |
| Payment information | Partial card or IBAN details reportedly accessed for some customers; EasyPark said they could not be used to make payments | ParkMobile said payment-card information was not accessed |
| Parking history | EasyPark said parking data was not compromised | ParkMobile said parking transaction history was not accessed |
| Password information | Hashed self-service passwords accessed for some notified customers | ParkMobile said encrypted passwords were accessed without encryption keys |
ParkMobile’s later notice describes its separate incident: ParkMobile security notification. A settlement page also concerns the earlier event: ParkMobile settlement information. Do not assume older reports of a specific total number of exposed credentials are confirmed by that later notice.
Quick Recap
What remains unknown?
- The total number of people affected across all brands and regions.
- The exact attack method and the specific systems or records accessed.
- Whether data was later published or misused; the company said it was unaware of such activity at the time of its notice.
- The final outcome of the Dutch criminal proceedings.
- The password-hashing algorithm and configuration used for the affected portal passwords.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




