Russian Federation
RUS
Attackers successfully compromised CarMoney systems during 17-18 February 2025. CarMoney confirmed that its IT infrastructure had been hacked and that it shut down all systems after attackers used company channels to send false messages to customers. The website and application became unavailable, payments could not be made through normal channels, and customers later continued to report payment disruptions and account-access problems; CarMoney waived late-payment penalties associated with the incident. Ukrainian Cyber Alliance self-claimed responsibility and alleged destructive activity and large-scale data compromise, but those claims were not independently verified.
Estimated severity
72 / 100
Source reliability
88 / 100
Approximate Date
18/02/2025
Targeted Company
CARMONEY
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Russian Federation
RUS
No other affected countries reported
Target country
Russian Federation
Affected countries
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
Please rotate your phone