[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3darame5klkbk":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":38,"isSpamList":38,"isMalware":38,"company":39},"68e3266eda11adda488251c3","eye4fraud","Eye4Fraud Data Breach","eye4fraud.com","2023-01-25T00:00:00.000Z","2023-03-06T04:46:58.000Z","2023-03-06T06:04:28.000Z","2026-07-20T01:53:17.254Z","Database leak","https:\u002F\u002Feye4fraud.com\u002Fstatement",[15,17,18,19],"https:\u002F\u002Feye4fraud.com\u002Fabout","https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Feye4fraud-2023","https:\u002F\u002Fwww.twingate.com\u002Fblog\u002Ftips\u002Feye4fraud-data-breach",16000591,"known",null,"unknown","Critical",[26,27,28,29,30,31,32],"Email addresses","IP addresses","Names","Partial credit card data","Passwords","Phone numbers","Physical addresses","\u003Cp>The January 2023 Eye4Fraud data breach affected 16,000,591 unique email addresses along with account, contact, address and partial card data.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The verified dataset contained email addresses, IP addresses, names, partial credit-card data, passwords, telephone numbers and physical addresses. \u003Cstrong>The 16,000,591 unique email addresses\u003C\u002Fstrong> are deduplicated addresses across 147 tables containing many more rows; the number does not establish an equal count of unique people or that every data type existed for each person. The corpus covered two main groups: direct users of the Eye4Fraud service and people who placed orders with other ecommerce merchants that used Eye4Fraud. Direct account records included names and bcrypt password hashes, while order tables contained names, telephone numbers, physical addresses and partial card information. Partial card data means the card type and last four digits; full card numbers and security codes are not confirmed data classes.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>Eye4Fraud officially confirmed that a backup file related to certain customers and containing limited information was subject to unauthorized access in January 2023. The company said it retained cybersecurity specialists and outside advisers, notified law enforcement and cooperated with the investigation. In February 2023, approximately 65 GB of data alleged to have come from Eye4Fraud was offered for sale on a criminal forum. The published material spanned tens of millions of rows across 147 tables, and verification identified 16,000,591 unique email addresses. \u003Cstrong>Bcrypt password hashes were associated only with direct service users\u003C\u002Fstrong>; the evidence does not show that ecommerce-account passwords belonging to shoppers were collected. Because the technical access method was not disclosed, a software flaw, phishing or insider access must not be presented as established cause.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>For direct Eye4Fraud account holders, the main risk is that a weak password or one reused elsewhere could be guessed from its bcrypt hash. People who ordered from merchants using Eye4Fraud may appear in the record even if they never created an Eye4Fraud account because transaction-screening data flowed through the service. A combination of name, telephone number, physical address, email, IP address and a card's last four digits can support convincing scams involving deliveries, order cancellation, refunds, payment verification or fake bank calls. The last four digits alone are insufficient to make a card payment, but real transaction context can strengthen social engineering. An email match does not prove that a full card number was exposed, a password was recovered or every listed data class belonged to the same person.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>If you had an Eye4Fraud account, replace its password with a long, unique credential and update every other account using the same or a similar password. Prioritize the primary mailbox, merchant administration panels, payment services and financial accounts. \u003Cstrong>Eliminate every reused password and enable multi-factor authentication\u003C\u002Fstrong>; adding a digit to an old password is not sufficient separation. Review active mailbox sessions, recovery addresses, forwarding rules and unfamiliar devices. If you shopped with a merchant using Eye4Fraud, inspect card activity and transaction alerts and report unfamiliar charges to the bank through its known channel. Do not follow links in messages about deliveries, refunds, orders or card verification; open the merchant or bank application yourself. Even when a caller knows the last four digits, never disclose a one-time code, full card number or security code.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Use a password manager to create a random, unique credential for every account so recovery of one hash cannot spread to other services. Prefer passkeys or phishing-resistant multi-factor authentication for email, finance and ecommerce administration. Enable bank and card alerts, and consider virtual or restricted cards for online purchases where available. Ecommerce businesses should minimize data sent to fraud-prevention providers, enforce retention limits and avoid leaving backups under the same access boundaries as production systems. Least-privilege administration, encrypted backups, access-log monitoring and rehearsed incident-notification plans reduce the impact of unauthorized access. Do not treat knowledge of genuine order details as proof that a message or caller is legitimate.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Use the secure search field on this page to check every current and historical email address that may have appeared in an Eye4Fraud account or an order screened by the service. A match means the address is among the 16,000,591 verified unique emails; it does not identify the originating table, prove that a password hash or partial card data existed on that row, or show that full card information leaked. If you receive a result, consider whether you were a direct service user or which merchants you shopped with, then prioritize password, mailbox and payment checks accordingly. Remove old password reuse, inspect account sessions and enable card alerts. Never enter a password, full card number, security code, one-time code or physical address into the search field. No result is an absolute guarantee because a differently written address, an order outside this corpus or another breach may still apply. Open the known merchant or financial institution domain directly instead of using links in suspicious messages.\u003C\u002Fp>","","Eye4Fraud Data Breach (16 Million Reported Records)","Eye4Fraud Data Breach. 16 Million reported records were reported. Reported data: Email addresses, IP addresses, Names. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Feye4fraud_com.webp",false,{"name":40,"sector":41,"country":42,"website":9,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":22},"Eye4Fraud","Fraud Prevention","United States"]