A threat actor has allegedly leaked a database belonging to HVMN, the performance nutrition company now operating under the Ketone-IQ brand, claiming to expose 86,904 user profiles containing customer information, subscription data, and payment-related metadata.
The alleged leak was published on August 5, with the actor claiming the data was obtained earlier that day. At the time of publication, HVMN had not issued any public statement addressing the claims.
Alleged customer database exposed
According to the threat actor, the leaked archive contains approximately 86,904 user profiles, including 57,209 unique email addresses, 44,474 unique full names, 48,201 unique IP addresses, and more than 39,000 unique Stripe customer IDs.
The post further claims the dataset contains 6,785 payment card records stored on file, although the actor states card numbers and CVV values are masked. Other allegedly exposed information includes subscription identifiers, shipping addresses, billing ZIP codes, revenue values, Google Analytics identifiers, account creation timestamps, and customer profile metadata.
The dataset is reportedly distributed as a 27 MB formatted JSON file and was made available as a free download. BreachNews has not verified the authenticity of the data or the claims made by the threat actor.
Latest claim from recurring actor
The same threat actor has recently published multiple alleged datasets targeting SaaS platforms, AI services, and technology companies. BreachNews previously reported the actor’s alleged Dante AI breach, in which they claimed to possess more than 73,000 user accounts containing customer information and analytics data.
In the HVMN post, the actor also teased another forthcoming alleged leak targeting Mailshake, claiming it would involve customer information and a significantly larger volume of analytics event data than previously disclosed. No evidence supporting that claim has been presented.
What users should watch for
If the claims are accurate, exposed information could be valuable for phishing, account takeover attempts, and identity-based fraud. Although the actor describes payment card numbers and CVV values as masked, the combination of customer identities, subscription details, shipping information, and Stripe customer identifiers could still enable convincing social engineering attacks.
Users of HVMN or Ketone-IQ should remain alert for unsolicited emails or messages requesting account verification, password resets, or payment updates, particularly if they reference recent purchases or subscription activity.
BreachNews has contacted HVMN for comment and will update this article if the company responds or publicly confirms the incident.












