According to Gemini Advisory, information from the Wawa hack surfaced on the Dark Web this week on Joker's Stash, one of the largest and most well-known dark web sites for purchasing stolen credit cards.

A data breach has hit Wawa, a convenience store/gas station, as hackers broke into over 850 Wawa stores and stole 30 million sets of payment statements, including those from Asian countries, making it one of the largest payment card breaches of all time.
According to Gemini Advisory, information from the Wawa hack surfaced on the Dark Web this week on Stash's Joker marketplace, one of the largest and most well-known dark web sites for buying stolen credit cards.
Gemini has determined that the point of entry for the breach, dubbed BIGBADABOOM-III, is Wawa, the convenience store/gas station. The company first discovered the breach on December 10, 2019.
“Large breaches of this type often have low demand on the dark web. This may be due to security researchers the point of entry,” Gemini said.
However, Joker's Stash uses media coverage of major breaches like this to bolster its credibility as the most notorious seller of compromised credit cards.
The full data includes 30 million records in more than 40 U.S. states, as well as over a million records from more than 100 different countries, Gemini said.
Wawa said reports that its customers' credit card information may be sold on the dark web are true.
Based on Gemini's analysis, the initial set of databases associated with "BIGBADABOOM-III" consisted of nearly 1,00,000 records.
While the majority of these records come from American banks and are linked to cardholders based in the US, some records are also linked to cardholders from Latin America, Europe , and several Asian countries.
“Cardholders who do not reside in the U.S. may be victims of this breach when traveling to the United States and making transactions at Wawa gas stations,” the report said.
