Description

Data belonging to over 1.3 million customers of the PandaBuy online shopping platform has been compromised in a significant breach, reportedly orchestrated by two threat actors who exploited multiple vulnerabilities within the system. PandaBuy serves as a gateway for international users to purchase goods from various Chinese e-commerce platforms like Tmall, Taobao, and JD.com. The breach was publicly claimed by a threat actor known as 'Sanggiero,' allegedly in collaboration with another actor named 'IntelBoker.' The leaked data, which includes sensitive information such as unique user IDs, names, phone numbers, emails, login IPs, orders data, home addresses, and more, was reportedly obtained by exploiting critical vulnerabilities in PandaBuy's API and other system bugs. The breach, affecting over 1.3 million PandaBuy accounts, was confirmed by data breach aggregation service Have I Been Pwned (HIBP). The compromised data, now circulating on a forum, is accessible to registered members for a nominal fee in cryptocurrency. To authenticate the validity of the leaked information, the threat actor has provided a sample containing email addresses, customer names, order details, shipping addresses, transaction timestamps, and payment IDs. Despite the breach, PandaBuy has remained silent on the matter, with reports suggesting attempts to suppress discussions on platforms like Discord and Reddit. However, users are advised to reset their passwords immediately and exercise caution regarding potential phishing attempts or suspicious communications. In response to the breach, HIBP has included PandaBuy user data in its database, and subscribers have been notified via email. While PandaBuy attempts to downplay the severity of the incident, users are urged to take proactive measures to safeguard their personal information and remain vigilant against potential security threats stemming from this breach.