A hacker leaked data from millions of registered users of Teespring – an online portal that allows users to create and sell custom clothing – on January 17. The data was exposed on a public forum related to cybercrime and the sale of stolen databases .

Teespring user data was made available as a 7zip archive containing two files . The first file contains a list of over 8 million email addresses, along with the date each email address was last updated. The second file contains account information for about 5 million users. In addition, the SQL file contains a hashed version of the email address, usernames, real names, phone numbers, home addresses, as well as the Facebook and OpenID tokens that users use to log in to accounts .

As ZDNet reports, the leak also exposes other information related to online accounts, but it is clarified that it is not believed to be sensitive data.
It’s worth noting that Teespring users didn’t fill out all of the information requested on the site, which reduces how much of their data was compromised by the breach. Additionally, password data is not included in the list of information compromised. However, it’s unclear whether the hacker gained access to passwords or simply chose not to publish them.

The hacker who leaked the data goes by the name ShinyHunters. This is a notorious hacking group that has leaked billions of user records from hundreds of companies. However, ShinyHunters is not believed to have breached Teespring.
The company's data was initially put up for sale on the same forum and through private Telegramin December 2020, before being leaked for free last week.
A Teespring spokesperson told ZDNet that the company discovered the breach, which it disclosed on December 1, 2020. The company also noted that the security incident took place in June 2020, when a hacker managed to steal user data from its cloud infrastructure.

The company added that it previously had a third-party service called “Waydev”that requested access to some of Teespring’s data. This access was accomplished through a technology called OAuth. Waydev held the OAuth token for Teespring and several other companies, which an unauthorized third party gained access to. The token was then used to access some of Teespring’s infrastructure.
It is noteworthy that Teespring, founded in 2011, is ranked in the 1,500 most popular sites and specifically ranks #1,410, according to Alexa.
