A threat actor has allegedly leaked the Shopify customer database belonging to Spytec GPS, claiming the breach exposed more than 131,000 customer records. The post includes a downloadable archive and a sample of the purported data, although the claims have not been independently verified by BreachNews.
The database was published on a cybercrime forum on July 20, with the threat actor alleging that Spytec GPS, a provider of GPS tracking devices for consumers and businesses, suffered a breach that exposed customer information.
Shopify customer database allegedly exposed
Spytec GPS sells GPS tracking devices for vehicles, fleets, assets, and personal safety. According to the forum post, the leaked data is purportedly a Shopify customer database containing customer account details, purchase history, and shipping information.
Customer records include purchase history and addresses
According to the forum post, the leaked Shopify database allegedly contains the following customer information:
- Customer IDs
- First and last names
- Email addresses
- Phone numbers
- Verified email status
- Order counts
- Total amount spent
- Purchase history
- Shipping and billing addresses
- Customer account status
- Email marketing consent status
- SMS marketing consent status
- Currency preferences
- Customer tags and notes
- Shopify GraphQL API identifiers
- Account creation and update timestamps
A sample accompanying the post appears to contain customer account information, historical order details, and shipping addresses. While no payment card information was listed in the alleged leak, the combination of names, contact details, purchase history, and physical addresses could increase the risk of targeted phishing, identity fraud, and scams impersonating Spytec GPS if the data is authentic.
Separate security incident disclosed in 2024
Spytec’s parent company, Hapn, previously disclosed a separate security incident in December 2024 after a website bug exposed information associated with approximately 8,600 GPS trackers. That confirmed incident involved customer names and tracker-related information rather than a Shopify customer database, and Hapn said the issue had been resolved. There is currently no evidence linking that incident to the newly alleged breach.
Spytec GPS yet to acknowledge alleged breach
Spytec GPS had not issued any public statement regarding the alleged breach at time of publication. BreachNews will update this article if the company responds or provides additional information about the alleged incident.












