HomeSecurityThousands of Instacart customer data available online

Thousands of Instacart customer data available online

The personal data of hundreds of thousands of Instacart customers is being sold on Dark Web sites . It includes names, the last four digits of credit card numbers and customer order history.

instacart

Two dark web sites were reportedly selling information from 278,531 accounts, some of which may be duplicates or fake, while Instacart said in April that it has “millions of customers in the US and Canada.”

However, the company denied that its data had been breached.

“We have not discovered a data breach at this time. We take data protection and privacy very seriously,” an Instacart spokesperson told BuzzFeed News. “Outside of the Instacart platform, attackers may target individuals using phishing or credential stuffing techniques. In cases where we become aware that account may have been compromised through an external phishing scam outside of the Instacart platform or other activity, we advise our customers to update their passwords.”

The source of the information, which also included email addresses and purchase data, was unknown, but it appears to have been uploaded between June and today.

“It looks recent and completely legitimate,” Nick Espinosa, head of cybersecurity firm Fanatics, told BuzzFeed News after reviewing the accounts being sold.

Thousands of Instacart customer data available online

Two women whose personal information was for sale confirmed that they were Instacart customers, that the date and amount of their last order matched those that appeared on the Dark Web, and that the credit card information belonged to them.

The account details were being sold for about $2 per customer. According to one of the websites where the information was being sold, the personal data of people using Instacart accounts had been added throughout June and July, with the most recent upload being on July 22.

We do not know the names of the websites selling this information. In cases of identity theft, there are certain steps that all users. Initially, it is necessary to change their password, use a password manager and activate two-factor authentication, where possible. In addition, if they notice any suspicious activity in their transactions, they should contact their bank or credit card company immediately.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS