A threat actor claims to have breached B-Stock Solutions and released a database containing information associated with approximately 42,118 user accounts.
The dataset was published on Sept. 4 and is described as containing more than 42,000 unique email addresses alongside account, device, location and bidding-related information. The actor made the alleged database available for download rather than offering it for sale.
The same threat actor previously claimed responsibility for the Right Inbox breach reported by BreachNews, which allegedly exposed 121,616 unique profiles and approximately 39.47 million activity records. That earlier post also connected the actor to separate Mailshake and ZoomShift breach claims.
Dataset allegedly contains account and bidding activity
The newly published B-Stock archive is described as a JSON Lines export containing approximately 42,118 unique accounts.
According to the fields disclosed by the actor, the information may include:
- Email addresses
- First and last names
- Phone numbers
- IP addresses
- Cities, regions and countries
- Device and operating system information
- Referral and registration information
- Search activity
- Product bid amounts and bid status
- Counts of bids won and lost
The sample records shared with the claim appear to contain marketing and web activity data in addition to account information. BreachNews is not reproducing the sample records or personal information contained in them.
The available post does not indicate that passwords, payment card numbers or bank account details are included in the released dataset.
B-Stock operates major B2B resale marketplace
B-Stock Solutions operates a business-to-business recommerce platform connecting companies selling returned, excess and trade-in inventory with commercial buyers.
The company describes its platform as supporting auctions, direct purchases and negotiated offers across a network of retailer and manufacturer marketplaces. B-Stock says its customers include major retailers, brands and manufacturers.
B-Stock’s privacy policy states that the company collects information including names, email addresses, phone numbers, business information, IP addresses, device characteristics and activity associated with its services. It may also collect bidding and purchasing information as part of transactions conducted through its platform.
The fields described in the alleged leak overlap with several categories of information B-Stock publicly says it collects, but that does not independently establish the authenticity or origin of the dataset.
Claim remains unconfirmed
The threat actor has provided sample records and a downloadable archive, but BreachNews has not independently verified that the dataset was obtained through a recent compromise of B-Stock systems.
The actor also has a limited public history under the current identity, so the claim should be treated cautiously until the dataset is independently validated or B-Stock confirms an incident.
B-Stock Solutions had not issued any public statement addressing the alleged breach at time of publication.











