A threat actor has published a collection of 12 databases allegedly obtained from websites spanning retail, professional services, nonprofit organizations, sports, language learning, and other sectors.
The forum post claims the release contains 11 CSV files and 1 SQL database with 14,453 records across most of the affected sites. A separate file allegedly linked to Tatoeba contains another 216,470 records consisting primarily of user IDs, usernames, and administrator status, bringing the combined number of listed rows to approximately 230,923.
The actor is offering the entire collection as a downloadable archive. BreachNews has not independently accessed or verified the contents of the archive.
Small websites bundled into a single release
The alleged leak names the following websites:
blusheshairsalon.combodygraphicstattoosupply.co.zaferminiatures.comknoxfocus.commesa.com.trmuseumtrade.orgsahabatgenpro.comskifederation.orgtatoeba.orgwebcomsystems.inweingut-topf.atwillrich.com
The actor described the websites as opportunistic targets discovered through search engine queries rather than organizations selected as part of a focused campaign.
Record counts vary substantially. The post claims only 12 records for one website, while others allegedly contain several thousand customer accounts. Tatoeba represents the largest file by row count, although the actor says its records contain only account identifiers, usernames, and administrative status.
WooCommerce exports expose more than account names
The most detailed samples were attributed to Blushes Hair Salon, Body Graphics Tattoo Supply, and FeR Miniatures. The records appear structured like WordPress and WooCommerce user exports containing customer account details and extensive account metadata.
The allegedly exposed information includes:
- Names, usernames, and email addresses
- Billing and shipping addresses
- Telephone numbers
- WordPress password hashes
- Customer roles and account registration dates
- Order and shopping cart information
- IP addresses and browser details
- Serialized login session data
- Payment processor customer identifiers
The published samples appear to include customer records dating primarily from 2016 through 2021. That suggests at least some of the material may come from older database exports rather than current customer systems, although the forum post does not explain when or how each database was allegedly obtained.
BreachNews is not reproducing the samples or any personal information contained in the post.
Session data and password hashes increase the stakes
The alleged exposure goes beyond ordinary marketing contact lists. WordPress password hashes could be targeted through offline password-cracking attempts, particularly where customers chose weak or reused passwords.
The samples also appear to contain serialized WordPress session information with historical IP addresses, browser user-agent strings, and login timestamps. While many of the listed sessions are likely expired, their inclusion indicates that the alleged exports may contain broad copies of user metadata rather than limited customer directories.
Billing addresses, telephone numbers, order history, and payment processor identifiers could also support targeted phishing or fraud attempts if the data is authentic. The post does not claim that plaintext passwords or complete payment card numbers were exposed.
Latest release from account behind Silvi AI claim
The multi-company release was published by the same forum account behind the recent alleged breach of Silvi AI, where the actor claimed an authorization flaw allowed the retrieval of 16,483 user records.
The account has a longer forum history than many newly created breach sellers and included detailed data fields and samples with this release. However, the affected organizations had not issued public statements confirming the alleged incidents at the time of publication.
The forum post advertises a downloadable archive containing the purported databases. BreachNews has not independently reviewed the files, but the published samples appear consistent with WordPress and WooCommerce account exports. This article will be updated if any of the named organizations confirm an incident or provide additional information about the alleged exposure.











