Threat actors Sangierro and IntelBroker have just leaked a huge database that allegedly contains the information of over 1.3 million PandaBuy customers.
PandaBuy is an online shopping platform that allows users to make purchases from multiple e-commerce shops from China.
In a post yesterday on the BreachForums community, one of the threat actors said “the data was stolen by exploiting several critical vulnerabilities in the platform’s API.”
“Other bugs were identified allowing access to the internal service of the website,” Sangierro added.
The stolen information uploaded on the hacker forum, currently up for grabs for small crypto payments by any registered members, includes:
- Full names of customers
- Contact details such as phone numbers and email address
- Login IP and order details
- Country of residence, home addresses and Zip codes
Choose pandabyt without any of the disadvantages of pandabuy