svwl01

A dataset tied to a Swvl Egyptian/Dubai-based bus-sharing & mass transit app has reappeared on a dark web forum. According to a new post spotted by cybersecurity researchers. The data was first breached in June 2020, but it is now being recirculated. It is raising fresh concerns for commuters across the UAE and neighboring markets like Egypt. Especially, those who may have used the platform.

An anonymous threat actor uploaded the dataset to a well-known deep web forum. The post claims to include information belonging to users of the app, and it has already drawn attention from several threat intelligence trackers who monitor forums for recycled or reissued breach data.

What Was Leaked

svwl02

According to the forum listing, the leaked database includes the following fields:

Leaked Data

svwl03

The threat actor has not disclosed how the data was originally obtained. Since the breach date traces back to June 2020, it is likely that this is a re-upload of an older dataset rather than a newly discovered intrusion. This pattern is common on dark web forums, where older breaches. They are repackaged, renamed, or reposted months or years later to attract new buyers.

  • Email addresses
  • Names
  • Partial credit card data
  • Passwords
  • Phone numbers
  • Profile photos

Why This Matters for Users in Dubai and Egypt

Mass transit and ride-sharing apps handle sensitive daily-use data, including travel patterns, payment details, and personal identifiers. When this kind of information resurfaces years after the original breach, the risk does not go away just because time has passed. Many users still reuse the same passwords across multiple accounts, which means old credentials can still be dangerous today.

For commuters in Dubai who rely on shared mobility apps for daily travel, and for users in Egypt. Similar transit and ride-sharing platforms are gaining popularity. This incident is a reminder that regional apps that handle location and payment data are frequent targets for threat actors seeking reusable, high-value datasets.

What Should Affected Users Do Now?

If you have ever used this app, or a similar bus-sharing or mass transit service in the UAE or Egypt, it is worth taking a few precautionary steps right away:

  • Change your password immediately, especially if you have used the same one on other accounts.
  • Enable two-factor authentication wherever the app or your linked email account supports it.
  • Watch out for phishing emails or SMS messages that reference your travel history or account details, since leaked data is often used to make scam messages look convincing.
  • Monitor your linked bank or payment cards for unusual activity if the app stored payment information.
  • Avoid clicking on any links claiming to offer a free breach check from unfamiliar sources, since these are often used to harvest more personal data.

A Growing Pattern of Recycled Breaches

This is not an isolated case. Across the Middle East and South Asia, older breaches involving transit apps, delivery platforms, and ride-sharing services continue to surface again on deep web forums. Threat actors often recognize that even outdated data still holds value. Many users never update their passwords after an initial breach.

For a fast-growing digital economy like the UAE, and a rapidly expanding tech and mobility sector in Egypt, this trend highlights. The importance of stronger data retention policies and quicker breach disclosure timelines from companies operating in the region.

By Raghav Bansal

Raghav Bansal has been working as a cybersecurity researcher for the past 8 years. He possesses strong research skills and specializes in crafting information related to cybersecurity and information security, covering almost all topics in the field. With a keen eye for detail and a dedication to staying updated with the latest trends and threats,