• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
Trending:
  • Kashmir
  • Elections
Saturday, June 6, 2026

Daily Times

Your right to know

  • HOME
  • Latest
  • Iran-Israel war
  • Gilgit Baltistan Election
  • Pakistan
    • Balochistan
    • Gilgit Baltistan
    • Khyber Pakhtunkhwa
    • Punjab
    • Sindh
  • World
  • Editorials & Opinions
    • Editorials
    • Op-Eds
    • Commentary / Insight
    • Perspectives
    • Cartoons
    • Letters to the Editor
    • Featured
    • Blogs
      • Pakistan
      • World
      • Lifestyle
      • Culture
      • Sports
  • Business
  • Sports
  • E-PAPER
    • Lahore
    • Islamabad
    • Karachi
Farhan Janjua

Farhan Janjua

Farhan Janjua is the Digital Editor, Daily Times. He's been a digital journalist for nearly 10 years now and writes on topics such as pop culture, media gossip, digital media, activism and youth politics. Notable previous associations include Dunya News, FutureChallenges.org by Bertelsmann Foundation, Global Voices and his award-winning blog Guppu.com. He tweets and Instagrams @FarhanJanjua.

Careem’s data breach is a threat to consumer rights, how can we protect ourselves?

Published on: April 26, 2018 10:34 PM

Careem has recently admitted to a data breach that occurred in its system that stores users and captains’ data in January this year. The breach was downplayed through a carefully drafted press release where it referred to the breach as a ‘cyber incident’. While it is indeed a ‘cyber incident’, it is one of huge magnanimity.

As Careem admits, the stolen data includes information such as names, E-Mail addresses, phone numbers, physical addresses and travel routes. Although the company insists that ‘there is no evidence’ of password and credit card data being compromised because passwords are encrypted and credit card information is stored on a third-party PCI compliant server, it advises in its recommendation to change passwords and to review bank and credit card statements for discrepancies. Imagine the nature of vulnerability this puts a user in and what this kind of information could mean in the wrong hands.

Dear Customers, we have identified a cyber incident that took place in January 2018 involving unauthorized access to the system we use to store data. Our wider security protocol keep passwords encrypted and credit card details on a separate system. pic.twitter.com/rkcpf671ct

— Careem (@careem) April 23, 2018

Here are my reasons for not taking this breach lightly

Identity theft

One thing that is considered gold by hackers and cyber fraudsters is identity information. They assume the identity of the affected person to gain access to malicious programmes and use this information for registration to systems.

Financial fraud

Even though Careem insists that there is ‘no evidence’ of credit card data being stolen, it is advising its customers to review bank and credit card statements for ‘suspicious activity’ and transaction discrepancies. Does this mean the company is unsure? If it falls into the wrong hands, this credit card information could result in unauthorised transactions. In simple words, it’s the end users who would lose money.

Could lead to another data breach

Since many users have same set of login credentials on other websites and apps as well, it’s highly likely the hackers could have gained access to your other online accounts; such as E-Mail addresses, social media networks and apps, which essentially means they could be robbed of more data and online information.

Blackmail, harassment and bullying

In an environment where users – especially women – already have apprehensions about using ride-hailing apps where their locations, phone numbers and identities are revealed to the captains, this data breach could bring more bad news. The hackers could use their contact information for cybercrimes like blackmailing, harassment and bullying.

https://twitter.com/4Bara/status/988442285485559809

What can you do about it?

Change your password immediately

It’s a no-brainer. Change your password immediately and review your personal information; such as travel history, frequently used routes, etc. and only delete the information which you don’t need stored.

Also, ensure you don’t use the same set of login credentials for other websites.

Block credit cards

I know this sounds extreme. But it’s not, given the breach of this data. Either get your bank to manually authorise credit card payments for you in which case you will have to ask your bank to open a session every time you need to do an online transaction, or get online transactions blocked on it. I know this is akin to setting the fledgling ecommerce industry of Pakistan back by a decade, but desperate times call for desperate measures.

User second numbers/double numbers

Most Careem captains already do this. Users can too. If you don’t have a second phone number, get a ‘double number’ which every network provider issues on your existing number and sim card. Use that as the primary identifier for your Careem accounts.

Review linked accounts

In the world of social connectivity, users’ information can be tracked online using their names, phone numbers or E-Mail addresses. One online search of a phone number can take you to the Facebook or WhatsApp profile of the customer if the same information is used across multiple platforms. It’s crucial for your online privacy to not link your social media accounts with each other.

While it is true that no company is immune to cyber-attacks and data thefts, companies of this magnitude have to be answerable in a more comprehensive manner and shouldn’t go scot-free. They have to answer to the local law enforcement and take users into confidence and offer compensation where it is due. Unfortunately, Pakistan lacks data protection legislation so it’s unlikely that Careem will be made to answer questions and pay for the breach.

In such a case, users have to be more vigilant and take things in own hands. Share as little information as possible.

The writer is the Digital Editor, Daily Times and can be reached at [email protected]. He tweets and instagrams @FarhanJanjua

Filed Under: Pakistan Tagged With: Careem, Careem Data breach, featured, Headline

Submit a Comment




Primary Sidebar




Latest News

Alexander Zverev eases past Jakub Mensik in French Open semifinals

Taylor to face Pili in Croke Park farewell

FIFA bans vuvuzelas from World Cup stadiums

France brush off Ivory Coast loss, call it timely World Cup reminder

Legendary boxer Muhammad Ali’s 10th death anniversary observed

Pakistan

JAAC declared proscribed party ahead of AJK polls on July 27

Fixed tax scheme for small retailers launched to raise Rs 50bn annually

Govt cuts petrol price by Rs 4 per litre, keeps diesel’s unchanged

Bilawal promises GB voters with land and job rights

Iran declares support for Hezbollah with wider peace deal in doubt

More Posts from this Category

Business

SBP’s ‘Go Cashless’ campaign saw Rs 34bn in digital transactions on Eid

Short-term inflation down by 0.56%

Saudi-Pak Business Council shows interest in infrastructure investment

‘Govt, allies united in efforts to craft people-centric budget’

Rupee records gain against US dollar

More Posts from this Category

World

CENTCOM space post signals wider US military footprint

US official delivers Trump’s “good hello” to Putin

NASA lifts ISS evacuation alert after leak

More Posts from this Category




Footer

Home
Lead Stories
Latest News
Editor’s Picks

Culture
Life & Style
Featured
Videos

Editorials
OP-EDS
Commentary
Advertise

Cartoons
Letters
Blogs
Privacy Policy

Contact
Company’s Financials
Investor Information
Terms & Conditions

Facebook
Twitter
Instagram
Youtube

© 2026 Daily Times. All rights reserved.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.