A threat actor is allegedly offering for sale a database claimed to belong to outdoor lifestyle retailer Huckberry, advertising nearly 386,000 customer records containing personal information and payment-related account metadata.
The sale listing, published on August 6, claims the database contains 385,955 records allegedly obtained during a breach dated August 5, 2026. At the time of publication, Huckberry had not issued any public statement addressing the claims.
Seller claims customer information exposed
According to the listing, the purported database contains customer UUIDs, first and last names, email addresses, street addresses, city, state, postal code, country, and multiple phone number fields.
The threat actor also claims the records include indicators showing whether PayPal was enabled on an account, along with Apple Pay merchant identifiers. The post advertises the dataset for sale rather than releasing it publicly.
BreachNews has not independently verified the authenticity of the alleged database or confirmed that the information originated from Huckberry.
Potential risk for customers
If authentic, the exposed information could be used in phishing campaigns, identity theft attempts, or other forms of social engineering. While the listing does not claim to include payment card numbers or passwords, the combination of contact information and payment platform metadata could allow attackers to craft convincing scams targeting affected customers.
Customers should remain cautious of unsolicited emails, phone calls, or text messages referencing Huckberry purchases or requesting account verification.
Huckberry had not issued any public statement at time of publication.











