Spytec GPS Data Breach Claim Exposes 131,000+ Customer Records

A threat actor claims to have leaked Spytec GPS's Shopify customer database, alleging the exposure of more than 131,000 customer records containing personal information and purchase history.
Screenshot of a cybercrime forum post claiming to leak Spytec GPS’s Shopify customer database, alleging the exposure of more than 131,000 customer records containing personal information, purchase history, and shipping addresses, with the purported data sample blurred.
A threat actor claims to have leaked Spytec GPS’s Shopify customer database, alleging the exposure of more than 131,000 customer records. The post describes the purported data as including customer information, purchase history, and shipping addresses.

A threat actor has allegedly leaked the Shopify customer database belonging to Spytec GPS, claiming the breach exposed more than 131,000 customer records. The post includes a downloadable archive and a sample of the purported data, although the claims have not been independently verified by BreachNews.

The database was published on a cybercrime forum on July 20, with the threat actor alleging that Spytec GPS, a provider of GPS tracking devices for consumers and businesses, suffered a breach that exposed customer information.

Shopify customer database allegedly exposed

Spytec GPS sells GPS tracking devices for vehicles, fleets, assets, and personal safety. According to the forum post, the leaked data is purportedly a Shopify customer database containing customer account details, purchase history, and shipping information.

Customer records include purchase history and addresses

According to the forum post, the leaked Shopify database allegedly contains the following customer information:

  • Customer IDs
  • First and last names
  • Email addresses
  • Phone numbers
  • Verified email status
  • Order counts
  • Total amount spent
  • Purchase history
  • Shipping and billing addresses
  • Customer account status
  • Email marketing consent status
  • SMS marketing consent status
  • Currency preferences
  • Customer tags and notes
  • Shopify GraphQL API identifiers
  • Account creation and update timestamps

A sample accompanying the post appears to contain customer account information, historical order details, and shipping addresses. While no payment card information was listed in the alleged leak, the combination of names, contact details, purchase history, and physical addresses could increase the risk of targeted phishing, identity fraud, and scams impersonating Spytec GPS if the data is authentic.

Separate security incident disclosed in 2024

Spytec’s parent company, Hapn, previously disclosed a separate security incident in December 2024 after a website bug exposed information associated with approximately 8,600 GPS trackers. That confirmed incident involved customer names and tracker-related information rather than a Shopify customer database, and Hapn said the issue had been resolved. There is currently no evidence linking that incident to the newly alleged breach.

Spytec GPS yet to acknowledge alleged breach

Spytec GPS had not issued any public statement regarding the alleged breach at time of publication. BreachNews will update this article if the company responds or provides additional information about the alleged incident.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site