Shopping platform PandaBuy data leak impacts 1.3 million users
ID: ed707cc5-7e91-5a50-9185-c63c1a724f7f
STIX ID: report--ed707cc5-7e91-5a50-9185-c63c1a724f7f
Feed Name: Bleeping Computer
A threat actor trio (claiming the names 'Sanggiero' and 'IntelBoker') announced a breach of PandaBuy after exploiting multiple API vulnerabilities and website bugs, leaking personal data for roughly 1.3 million valid user accounts (emails, names, phone numbers, addresses, order data). The stolen dataset was posted for sale on a forum with sample records to prove validity and Have I Been Pwned confirmed the account list, while PandaBuy has not issued a full public statement and some company representatives have suggested the data may be old.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
