Pattons Shipping Database Allegedly Leaked With Customer and Shipment Data

A threat actor claims to have leaked a Pattons shipping database containing customer contacts, shipment records, addresses, invoices and logistics information.
Cybercrime forum post claiming a Pattons Australia myTNT shipping database was leaked with customer, shipment, billing and logistics data.
A threat actor published what they claim is a Pattons Australia myTNT shipping database containing contact details, shipment records, addresses, billing information and other logistics data. The post included a sample presented as proof of access.

A threat actor claims to have leaked a shipping database belonging to Australian custom fabric specialist Pattons, potentially exposing customer and logistics information associated with shipments processed through TNT and FedEx services.

The database was advertised on Sept. 1, 2026 and described as a Pattons myTNT shipment database. The actor claims it contains shipping account and booking numbers, tracking information, names, company details, email addresses, phone numbers, postal addresses, shipment details, invoice information and other logistics records.

A screenshot presented as proof of access appears to show structured shipment records containing Pattons sender information alongside collection contacts, companies, phone numbers, email addresses and addresses. BreachNews is not reproducing the personal information visible in the sample.

Leaked records appear tied to shipping operations

The alleged database appears focused on Pattons’ use of TNT shipping services rather than a conventional website customer database.

The threat actor claims the compromised information includes:

  • Shipping account, booking and shipment reference numbers
  • Tracking and delivery information
  • Names and company names
  • Email addresses and phone numbers
  • Postal, collection and return addresses
  • Shipment dates and delivery status
  • Goods descriptions, values, weights and volumes
  • Pricing, billing and payment terms
  • Invoice and customs information
  • Collection and delivery instructions
  • Return shipment information

The actor also claims the data contains tax information, Incoterms and dangerous goods codes associated with some shipments.

BreachNews has not independently established the total number of records in the database or confirmed that every data category claimed by the actor is present.

Sample contains information consistent with Pattons

The evidence supplied with the leak claim contains details that correspond with publicly available information about Pattons.

The sample identifies Botany, New South Wales as a sender location and contains company contact information associated with the pattons.com.au domain. Pattons’ official website identifies its Sydney headquarters as being in Botany and describes the company as a designer, fabricator and installer of custom fabric solutions.

Pattons says it has operated since 1953 and works across architectural fabric structures, industrial textiles, sporting events and other specialized fabrication projects.

The consistency between the sample and public company information gives the claim additional credibility, but does not establish how the records were obtained or whether the database was taken directly from Pattons infrastructure.

FedEx and TNT data does not establish FedEx breach

The presence of TNT and FedEx-related shipment information is an important distinction in assessing the incident.

FedEx operates TNT services in Australia, including domestic shipping services for Australian businesses. A Pattons database containing records generated through those services does not by itself indicate that FedEx or TNT infrastructure was compromised.

The actor specifically characterized the material as a Pattons shipping database. Based on the currently available evidence, BreachNews is treating Pattons as the alleged affected organization and is not attributing the exposure to a breach of FedEx.

Shipping records create fraud and impersonation risks

If authentic, the exposed information could provide attackers with detailed context for targeted phishing, business email compromise and shipment-related impersonation attempts.

Information combining company contacts with shipment references, delivery addresses, goods descriptions, invoice details and logistics information could allow criminals to construct convincing messages impersonating suppliers, couriers or business partners.

Shipment and collection records may also expose information about Pattons’ commercial relationships and operational activity.

The threat actor made the alleged database publicly downloadable rather than merely advertising possession of the information.

Pattons had not issued any public statement regarding the alleged data exposure at time of publication.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site