12 Websites Reportedly Breached as Customer Databases and Password Hashes Leak

A threat actor has released databases allegedly tied to 12 websites, exposing customer accounts, password hashes, addresses, session metadata, and payment identifiers.
Edited screenshot of a forum post titled “12 databases - Leaked, Download” in which a threat actor claims to have leaked databases from 12 organizations. The screenshot has been redacted by removing the large sample database code blocks to improve readability while preserving the post’s title, claimed record counts, and list of affected websites.
Forum post in which a threat actor claims to have leaked databases from 12 organizations. BreachNews removed the embedded sample data from the screenshot to avoid republishing potentially exposed information while preserving the post’s key claims and list of alleged victims.

A threat actor has published a collection of 12 databases allegedly obtained from websites spanning retail, professional services, nonprofit organizations, sports, language learning, and other sectors.

The forum post claims the release contains 11 CSV files and 1 SQL database with 14,453 records across most of the affected sites. A separate file allegedly linked to Tatoeba contains another 216,470 records consisting primarily of user IDs, usernames, and administrator status, bringing the combined number of listed rows to approximately 230,923.

The actor is offering the entire collection as a downloadable archive. BreachNews has not independently accessed or verified the contents of the archive.

Small websites bundled into a single release

The alleged leak names the following websites:

  • blusheshairsalon.com
  • bodygraphicstattoosupply.co.za
  • ferminiatures.com
  • knoxfocus.com
  • mesa.com.tr
  • museumtrade.org
  • sahabatgenpro.com
  • skifederation.org
  • tatoeba.org
  • webcomsystems.in
  • weingut-topf.at
  • willrich.com

The actor described the websites as opportunistic targets discovered through search engine queries rather than organizations selected as part of a focused campaign.

Record counts vary substantially. The post claims only 12 records for one website, while others allegedly contain several thousand customer accounts. Tatoeba represents the largest file by row count, although the actor says its records contain only account identifiers, usernames, and administrative status.

WooCommerce exports expose more than account names

The most detailed samples were attributed to Blushes Hair Salon, Body Graphics Tattoo Supply, and FeR Miniatures. The records appear structured like WordPress and WooCommerce user exports containing customer account details and extensive account metadata.

The allegedly exposed information includes:

  • Names, usernames, and email addresses
  • Billing and shipping addresses
  • Telephone numbers
  • WordPress password hashes
  • Customer roles and account registration dates
  • Order and shopping cart information
  • IP addresses and browser details
  • Serialized login session data
  • Payment processor customer identifiers

The published samples appear to include customer records dating primarily from 2016 through 2021. That suggests at least some of the material may come from older database exports rather than current customer systems, although the forum post does not explain when or how each database was allegedly obtained.

BreachNews is not reproducing the samples or any personal information contained in the post.

Session data and password hashes increase the stakes

The alleged exposure goes beyond ordinary marketing contact lists. WordPress password hashes could be targeted through offline password-cracking attempts, particularly where customers chose weak or reused passwords.

The samples also appear to contain serialized WordPress session information with historical IP addresses, browser user-agent strings, and login timestamps. While many of the listed sessions are likely expired, their inclusion indicates that the alleged exports may contain broad copies of user metadata rather than limited customer directories.

Billing addresses, telephone numbers, order history, and payment processor identifiers could also support targeted phishing or fraud attempts if the data is authentic. The post does not claim that plaintext passwords or complete payment card numbers were exposed.

Latest release from account behind Silvi AI claim

The multi-company release was published by the same forum account behind the recent alleged breach of Silvi AI, where the actor claimed an authorization flaw allowed the retrieval of 16,483 user records.

The account has a longer forum history than many newly created breach sellers and included detailed data fields and samples with this release. However, the affected organizations had not issued public statements confirming the alleged incidents at the time of publication.

The forum post advertises a downloadable archive containing the purported databases. BreachNews has not independently reviewed the files, but the published samples appear consistent with WordPress and WooCommerce account exports. This article will be updated if any of the named organizations confirm an incident or provide additional information about the alleged exposure.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site