Budget Saudi Confirms Mobile App Data Breach: Customer PII Exposed, Financial Data Unaffected

Budget Saudi has confirmed unauthorized access to customer data via its mobile app, as disclosed on Tadawul. The firm, which manages 29,000+ vehicles, stated no financial or banking data was compromised. PDPL reporting obligations to the Saudi Data and AI Authority (SDAIA) are now active.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region3 min read
Customer in Saudi Arabia viewing a car rental mobile application following the Budget Saudi data breach confirmation of unauthorised access to customer personal data through its app in June 2026

Customer in Saudi Arabia viewing a car rental mobile application following the Budget Saudi data breach confirmation of unauthorised access to customer personal data through its app in June 2026

Budget Saudi Arabia, formally the United International Transportation Company and one of the largest vehicle leasing operators in the Middle East and North Africa, has confirmed a cybersecurity incident in which unauthorised access to customer data occurred through the company's mobile application. The disclosure was made via the Saudi Exchange (Tadawul) on 10 June 2026. The company confirmed it promptly activated approved security measures upon discovering the incident, implemented technical containment measures, and initiated verification and technical evaluation in coordination with the relevant authorities. All systems and business operations continue to run normally.

What Was and Was Not Compromised

Budget Saudi confirmed that no customer financial or banking information was compromised. The breach was limited to a subset of customer personal data accessed through the mobile application. The company has not publicly quantified the number of affected customers or specified the categories of personal data exposed, beyond confirming that financial and banking data were outside the scope of the breach. Budget Saudi operates more than 29,000 vehicles across a network of 100 retail stations in 25 cities across the region. Its Q1 2026 financial results showed a 58 percent year-on-year decline in net profit to 34 million SAR. As a Tadawul-listed entity, the breach triggered a mandatory stock exchange disclosure.

Regulatory Obligations Under PDPL

This incident carries direct implications under Saudi Arabia's Personal Data Protection Law, enforced by SDAIA. Organisations that suffer a breach involving personal data must notify SDAIA within 72 hours of becoming aware of the incident, and, where the breach is likely to cause harm to data subjects, must notify affected individuals directly. The NCA's draft National Framework for Cybersecurity Information Sharing and Incident Response, open for consultation since 10 June 2026, would require detailed post-incident reporting including root cause analysis, indicators of compromise, and estimated financial impact. While the NFCISIR framework is not yet in force, Budget Saudi's response will be evaluated against the NCA Essential Cybersecurity Controls already in effect.

The Application Security Gap

This incident illustrates a vulnerability profile consistently underestimated by GCC enterprises: consumer-facing mobile applications. The Mastercard Cyber Pulse EEMEA report, released this week, identified application security as one of the two most consistently observed cyber health gaps across the region. Mobile applications that handle customer personal data without adequate input validation, authentication controls, and data access restrictions represent a persistent and well-understood attack surface.

What Customers Should Do

Budget Saudi customers who use the company's mobile application should monitor their accounts for unusual activity. While financial data was not compromised, exposed personal data including names and contact details can be used in follow-on phishing and social engineering attacks. Treat any unexpected communication from Budget Saudi requesting personal information or urgent action with caution, regardless of how official it appears.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

Saudi Arabia Cyber RegulationGCC Threat IntelligenceMobile Security MENAData Breach GCCMENA Enterprise Security