HomeSecurityPandaBuy: Data breach affects 1.3 million customers

PandaBuy: Data breach affects 1.3 million customers

Online shopping platform PandaBuy has reportedly suffered a data breach affecting more than 1.3 million customers. The attackers claim to have exploited multiple vulnerabilities to compromise the platform and leak the stolen data.

PandaBuy Data Breach

PandaBuy allows users from all over the world to purchase products from various e-commerce platforms in China, including Tmall, Taobao, and JD.com.

The day before yesterday, a cybercriminal named “Sanggiero” claimed to be behind the PandaBuy data breach, along with another attacker named “IntelBoker.”

See also: Harvard Pilgrim: Data breach affected 2,860,795 people

The data was stolen by exploiting several critical vulnerabilities in the platform’s API, and other bugs were identified that allowed access to the site’s internal service,” the attacker said.

The data contained 3 million+ unique UserIds, names, surnames, phone numbers, emails, login IPs, orders_data, orders_Ids, home addresses, countries, and so on.“.

PandaBuy buyer details were leaked to a forum, whose members can obtain them by paying a symbolic amount in crypto.

To prove to unregistered members that the information is valid, the attacker provides a small sample of emails, customer names, order numbers and details, shipping addresses, transaction dates and times, and payment IDs.

See also: Hot Topic: Customer data breach?

Have I Been Pwned (HIBP) investigated the PandaBuy data breach and found that at least 1,348,407 accounts were exposed . The remaining email addresses are fabricated and duplicate addresses, so the “3 million” number was inflated by threat actors.

PandaBuy has not made any statement regarding the data breach. A company spokesperson who is an admin on the Discord channel said that a security incident had occurred in the past and that the leaked data was old, while the security had responded promptly to the issue.

Users who have an account on PandaBuy should reset their password and be very careful with emails, messages or phone calls they may receive, as cybercriminals may use the exposed data to commit fraud.

See also: Fujitsu: Detects malware in systems and breach of customer data

PandaBuy: Data breach affects 1.3 million customers
PandaBuy: Data breach affects 1.3 million customers

They can also closely monitor their bank transactions and credit cards for any suspicious activity. If they notice any unusual activity, they should notify bank .

Finally, it is recommended that they use a manager password. This will allow them to create and store strong and unique passwords for each of their accounts, thus reducing the risk of further leaks.

The data has been added to HIBP and subscribers to the service will likely have received an email informing them of the leak.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS