[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$frjjcnbw4pf1f":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":25,"seoTitle":15,"seoTitleEn":26,"seoDescription":15,"seoDescriptionEn":27,"logoUrl":28,"isVerified":4,"isSensitive":29,"isSpamList":29,"isMalware":29,"company":30},"68e3266eda11adda4882529f","market-moveis","Market Moveis Data Breach","marketmoveis.pt","2023-08-30T00:00:00.000Z","2024-09-01T07:22:42.000Z","2026-07-03T23:13:31.112Z","2026-07-18T23:53:57.415Z","Third party breach","",[],28220,"known",null,"unknown","Medium",[23,24],"Email addresses","Names","\u003Cp>The Market Moveis data breach is related to the Portuguese home decor and furniture retailer exposing customer records in the August 2023 period. The scope is approximately 28,220 records. This was treated as a limited-scope retail customer data breach; the company, country, sector, website, and data class fields were rechecked. Since the only verified fields were name and email, the risk was not escalated.\u003C\u002Fp>\u003Cp>The text was rewritten to directly convey risk and action to the user. The website domain was kept as marketmoveis.pt; since the protocol was not added, a format that would cause https to appear twice on the link side was not used. The country was corrected to Portugal instead of United States, and the industry was corrected to home decor retail.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data seen in this record are email addresses and names. Password, phone, address, or payment card fields were not verified. Unverified payment card, bank account, private message, official ID, health record, or additional profile fields were not added to the data class list; only supported fields were left.\u003C\u002Fp>\u003Cp>Name and email matching can be used in fake campaigns, order notifications, or customer service messages. An email address alone poses a risk of spam; when combined with a phone number, address, IP, date of birth, photo, ID number, or device tracking data, it becomes easier for an attacker to create messages specific to the user. Therefore, the risk is assessed not only based on the number of records but also on the combinability of the data.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The scope was confirmed with record 28,220 dated August 2023. While the verified fields were retained, the unconfirmed fields were left out. The incident was not combined with other brands, records with similar names, or incidents from different periods of the same company.\u003C\u002Fp>\u003Cp>The incident was limited to the domain marketmoveis.pt and additional customer domains were not added to the data class. This approach prevents duplicate breaches from being added and prevents the user from being shown incorrect organizational responsibility. The domain, company name, and sector information were kept in the narrowest accurate context possible; where there was uncertainty, a verified flag or website domain was set accordingly.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>User groups at risk may be customers who have opened an account on the Market Moveis site, reviewed products, or left a contact form. Matched users should also evaluate other accounts where they use the same email, phone, username, or password pattern, apart from the relevant account.\u003C\u002Fp>\u003Cp>Home decoration or order-themed messages can be used to direct the user to fake links. If there is a corporate email, child or family account, public record, gaming identity, literacy community, monitoring software, or professional service context, the social engineering risk may increase. Users should not accept details that seem correct about themselves as a sign of trust.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should verify campaign, order, or account update messages received on behalf of Market Moveis through the official website. For accounts with a password field, all accounts using the same password should be updated; for accounts without a password field, the focus should be on the risks of phone, email, fake notifications, and identity matching.\u003C\u002Fp>\u003Cp>Instead of clicking on the links in the message, the address of the relevant service should be typed manually or the record in a trusted password manager should be used. Messages regarding cargo, support, game rewards, account warnings, public records, security notifications, document sharing, or subscription renewal should not be accepted without verification through an independent channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Marketing permissions in retail accounts should be reduced, and only necessary contact information should be shared. Users should regularly clean up old accounts, unnecessary profile fields, duplicate usernames, and old phone and address information. A unique password for each service and two-step verification where possible should be a basic rule.\u003C\u002Fp>\u003Cp>From the perspective of service providers, data minimization, strong password protection, monitoring of access logs, deletion of unnecessary fields, and having user notification processes ready are required. Even limited data such as name and email may be sufficient for brand impersonation messages. Accurate scope explanation is also part of the security work; exaggerated or incomplete information can lead the user to take incorrect action.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The user should first check this record using the email address. If a match is found, it should be accepted that the name and email information can be used in targeted messages, and store links should be manually verified. The absence of a match does not completely rule out the use of a different email or the reuse of an old password; critical accounts should also be reviewed.\u003C\u002Fp>\u003Cp>This record remained verified; sensitive flag and additional data fields were not added because they were not verified. In this edit, data fields were left as English canonical classes, the description visible to the user was written in Turkish and original, unverified fields were not added, and the sensitivity flag was used only when supported by the risk context.\u003C\u002Fp>","Market Moveis Data Breach (28.2 Thousand Reported Records)","Market Moveis Data Breach. 28.2 Thousand reported records were reported. Reported data: Email addresses, Names. Review the scope, risks, and protective steps.","\u002Fuploads\u002Flogo\u002Fmarketmoveis_pt.webp",false,{"name":31,"sector":32,"country":33,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Market Moveis","Retail \u002F Home Decor","Portugal"]