A threat actor attempted to sell an alleged customer registry containing sensitive identity profiles on a dark web forum. While Europcar disputed the systemic authenticity of the data, the file structures included consumer names, residential locations, and redacted identity numbers.