MyPhoto Allegedly Exposed Customer Order Data Through Misconfigured Firebase

A threat actor claims a publicly accessible Firebase database exposed MyPhoto customer order information, production records, and employee data without authentication.
Cropped screenshot of a forum post alleging that MyPhoto exposed a publicly accessible Firebase Realtime Database containing customer order information, employee records, production workflow data, and shipping details. The screenshot summarizes the alleged exposed data categories and record counts while omitting lower sections of the original post.
Cropped screenshot of the alleged MyPhoto database exposure post. The screenshot summarizes the claimed Firebase misconfiguration and alleged exposed data categories. The database URL and other potentially sensitive technical details have been redacted, and lower sections containing sample data have been omitted for safety and readability.

A threat actor claims to have discovered a publicly accessible Firebase Realtime Database belonging to MyPhoto, a U.S.-based photo fulfillment and print-on-demand company, allegedly exposing customer order information, employee data, and internal production records without authentication.

Unlike many breach claims involving stolen databases, the post alleges the information was accessible because of a misconfigured Firebase Realtime Database rather than a traditional network intrusion. According to the threat actor, the database allowed anonymous read access and exposed operational data used throughout MyPhoto’s production and fulfillment pipeline.

MyPhoto had not issued any public statement at time of publication.

Database allegedly exposed customer orders and production systems

According to the forum post, the exposed database contained approximately 16,272 customer email addresses linked to photo orders, 171,047 order line items, 21,126 image tag records connecting customer email addresses to specific photo orders, and 207 production orders containing fulfillment information.

The threat actor also claims the database included shipping information, order confirmation identifiers, product SKUs, delivery dates, image and PDF references, shipping dimensions, serial numbers, customer phone numbers, billing addresses, and fulfillment metadata. The post further alleges that a small number of completed shipments, including carrier tracking information, were also present within the database.

Beyond customer information, the alleged exposure reportedly included internal operational data such as employee records, production workflows, workstation assignments, product categorization data, and organization structures associated with MyPhoto’s manufacturing and fulfillment process.

Misconfigured Firebase allegedly responsible

The threat actor claims the exposed data originated from a Firebase Realtime Database configured to allow anonymous access without authentication. According to the post, the database remained publicly readable through standard Firebase requests, allegedly exposing dozens of database collections supporting production, inventory, shipping, quality control, and order management.

The post describes the dataset as a complete Firebase Realtime Database export totaling approximately 158 MB in raw JSON format, accompanied by extracted customer, employee, and production data.

BreachNews has not independently verified the authenticity of the claims or confirmed whether the database was publicly accessible at the time of publication.

Exposure could enable highly targeted phishing

If the claims are accurate, the exposed information could enable highly targeted phishing campaigns by allowing attackers to associate customer email addresses with specific photo orders, fulfillment dates, and shipping activity. Internal employee information and production workflow data could also increase the risk of social engineering attacks targeting operational staff.

Although the post does not claim payment card numbers were exposed, the combination of customer contact information, order details, shipping metadata, and internal operational records could provide attackers with sufficient context to craft convincing fraudulent communications.

The alleged MyPhoto exposure is one of several Firebase-related database claims published by the same threat actor in recent days. Other posts have alleged similar exposures affecting Cars Software AS, American Auto Shipping, Allstate Tax LLC, BudBoard.co, and Qara.net. Those claims have not been independently verified by BreachNews.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site