Fanjoy Data Breach Claim Exposes 467,000+ Customer Order Records

A threat actor claims to have leaked Fanjoy's order database, alleging the exposure of more than 467,000 customer records containing order, shipping, and customer information.
Screenshot of a cybercrime forum post claiming to leak Fanjoy.co’s order database, alleging the exposure of more than 467,000 customer order records containing shipping and billing information, with the purported data sample blurred.
A threat actor claims to have leaked Fanjoy’s order database, alleging the exposure of more than 467,000 customer records. The post describes the purported data as including customer details, shipping and billing addresses, order information, and platform metadata.

A threat actor has allegedly leaked the order database belonging to Fanjoy, an influencer merchandise platform, claiming the breach exposed more than 467,000 customer records. The post includes a downloadable archive and a sample of the purported data, although the claims have not been independently verified by BreachNews.

The database was published on a cybercrime forum on July 20, with the threat actor alleging that Fanjoy suffered a breach exposing customer order information, shipping details, and purchase records.

Influencer merchandise platform allegedly targeted

Fanjoy operates an e-commerce platform that enables online creators, musicians, and influencers to sell branded merchandise directly to fans. Over the years, the company has partnered with numerous high-profile internet personalities and fulfilled millions of merchandise orders through its online storefront.

Order database allegedly includes customer and shipping information

According to the forum post, the leaked database allegedly contains the following order information:

  • Order IDs and order numbers
  • Customer account IDs
  • Email addresses
  • Order totals
  • Order status information
  • IP addresses
  • Order creation and update timestamps
  • Shipping names
  • Shipping addresses
  • Billing names
  • Billing addresses
  • Phone numbers
  • Line items
  • Shipment information
  • Payment metadata
  • Platform store identifiers

A sample accompanying the post appears to contain customer order information, including shipping and billing details, order totals, and contact information. While the threat actor does not claim payment card numbers were included, the alleged combination of names, addresses, phone numbers, email addresses, purchase history, and IP addresses could increase the risk of phishing, identity fraud, and scams impersonating Fanjoy if the data is authentic.

Latest breach claim from the same threat actor

The alleged Fanjoy leak was published by the same threat actor who earlier claimed responsibility for an alleged breach affecting Spytec GPS. While the actor has published multiple database disclosures, the Fanjoy claims should still be treated as unverified until independently confirmed.

Fanjoy yet to acknowledge alleged breach

Fanjoy had not issued any public statement regarding the alleged breach at time of publication. BreachNews will update this article if the company responds or provides additional information about the alleged incident.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site
INTEL.BREACHNEWS.COM

Live Cyber
Threat Map

Explore live cyber activity, recent breach reports, KEV alerts, and public threat feeds from a single interactive dashboard.

Launch Threat Map