[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f34c9pw3ta0iop":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":16,"affectedCount":16,"affectedCountStatus":17,"affectedCountLowerBound":18,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":26,"seoTitle":27,"seoTitleEn":28,"seoDescription":27,"seoDescriptionEn":29,"logoUrl":30,"isVerified":4,"isSensitive":31,"isSpamList":31,"isMalware":31,"company":32},"68e3266eda11adda48825246","james","James Delivery 2020 Data Breach","jamesdelivery.com.br","2020-03-25T00:00:00.000Z","2020-11-05T04:34:51.000Z","2026-07-29T17:57:15.135Z","Verified breach record","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fseller-floods-hacker-forum-with-data-stolen-from-14-companies\u002F",[14],1541284,"known",null,"email_identifiers","Critical",[22,23,24,25],"Email addresses","Geographic locations","Latitude and longitude pairs","Passwords","\u003Cp>\u003Cstrong>The James Delivery 2020 data breach\u003C\u002Fstrong> concerns account and location data attributed to the Brazil-based delivery service. A verified external breach record dates the event to March 25, 2020 and contains 1,541,284 unique email addresses. Contemporary independent reporting says a data broker advertised approximately 1.6 million JamesDelivery records in June 2020. The exact unique-email count and the rounded sale-listing figure are separate measures.\u003C\u002Fp>\n\n\u003Ch2>Which data types were confirmed?\u003C\u002Fh2>\n\u003Cp>The verified external record contains email addresses, general geographic locations, latitude-longitude pairs, and bcrypt password hashes. The presence of location fields does not prove that they represent homes, workplaces, delivery points, or order history. Coordinate precision also does not mean that every row contained a location or that the location was current.\u003C\u002Fp>\n\u003Cp>Names, phone numbers, full street addresses, payment cards, bank accounts, order contents, and device information are not confirmed data types for this event. A bcrypt hash is not a plaintext password, although weak or reused passwords can still be exposed to offline guessing risk.\u003C\u002Fp>\n\n\u003Ch2>Why do 1,541,284 and 1.6 million differ?\u003C\u002Fh2>\n\u003Cp>The 1,541,284 value represents unique email addresses in the verified external corpus. Approximately 1.6 million is the rounded record count reported for the contemporary sale listing and was not defined as unique people, accounts, or emails. The values are not added together and should not be used interchangeably.\u003C\u002Fp>\n\u003Cp>A production check found no James import job or locally linked data in the email, password, location, or other person-level collections. The exact external email value is therefore presented only with its own measurement unit, without implying that it is a local total or imported-record count.\u003C\u002Fp>\n\n\u003Ch2>What is the confidence boundary of the sources?\u003C\u002Fh2>\n\u003Cp>The verified breach record supplies the exact email count, event date, four data types, and bcrypt detail. Independent reporting dated June 29, 2020 supplies the JamesDelivery name in the sale listing, the approximately 1.6 million-record figure, and the observation that reviewed samples appeared legitimate; the same report explicitly says the companies had not directly confirmed the events and that James had not responded.\u003C\u002Fp>\n\u003Cp>An older secondary security article linked by the index now returns 404. A November 28, 2020 Wayback capture shows that it summarized the same sale-listing report, so it was not counted as separate confirmation. jamesdelivery.com.br is currently reachable, and an incident-period archive supports the service identity, but the existence of the company site is not breach evidence.\u003C\u002Fp>\n\n\u003Ch2>Which risks can reasonably be inferred?\u003C\u002Fh2>\n\u003Cp>Linking an email address with location data and a password hash can support targeted phishing and attempts against reused passwords on other sites. If a password used with James during this period was reused elsewhere, it should be replaced with a unique password, multi-factor authentication should be enabled on the email account, and links in unexpected delivery or password-reset messages should be avoided.\u003C\u002Fp>\n\u003Cp>An email match does not show that a person's home or workplace, orders, or payment information was exposed. The confirmed boundary for this record is email, general location, coordinates, and bcrypt hash fields; broader inferences about personal behavior or harm should not be made.\u003C\u002Fp>","","James Delivery 2020 Data Breach (1.5 Million Email Identifiers)","The 2020 James Delivery breach contains 1,541,284 verified unique emails. Review location data, bcrypt password hashes, and the scope boundary.","\u002Fuploads\u002Flogo\u002Fjamesdelivery_com_br.webp",false,{"name":33,"sector":34,"country":35,"website":9,"websiteArchiveUrl":27,"websiteStatus":36,"websiteCheckedAt":37},"James","Logistics","Brazil","active","2026-07-29T17:48:09.000Z"]