[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1pfyth73r7box":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":36,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda4882529e","MastercardPricelessSpecials","Mastercard Priceless Specials Data Breach","mastercard-priceless-specials","specials.mastercard.de","2019-08-20T00:00:00.000Z","2019-09-01T20:37:49.000Z","2026-07-18T23:53:59.749Z","Loyalty program breach","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fdata-of-90k-mastercard-priceless-specials-members-shared-online\u002F",[15,17,18],"https:\u002F\u002Fwww.cyberdefensemagazine.com\u002Fmastercard-data-breach-affected-priceless-specials-loyalty-program\u002F","https:\u002F\u002Fspecials.mastercard.de\u002F",89388,"known",null,"unknown","Medium",[25,26,27,28,29,30],"Email addresses","IP addresses","Names","Partial credit card data","Phone numbers","Salutations","\u003Cp>The Mastercard Priceless Specials data breach is a verified financial loyalty program incident affecting 89,388 program members tracked in Mastercard's loyalty and campaign program in Germany as of August 20, 2019. The types of data recorded include email addresses, IP addresses, name information, partial credit card data, phone numbers, and salutation information. This incident should not be treated as a password leak; there are no passwords in the verified data classes. The risk mainly revolves around phishing, phone scams, cardholder impersonation, campaign message forgery, and personal profile matching.\u003C\u002Fp>\n\u003Cp>Since Priceless Specials is a campaign and benefits program associated with the Mastercard brand, leaked data becomes valuable for preparing fake messages that appear trustworthy to users. Name, phone, email, and salutation information make scenarios like fake customer service calls or reward program notifications more convincing. Partial credit card data should not mean the full card number, expiration date, or CVC code; however, when combined with other information about the cardholder, it can still increase the risk of impersonating a bank or card support line.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The email addresses in the Mastercard Priceless Specials records can be used for fake campaign, reward point, card security, or account verification messages. Name and salutation information makes these messages more personal. Users with phone numbers can be targeted via fake card alerts by SMS or customer service impersonation over the phone. IP addresses do not provide an exact home address but can offer limited clues about the user's general connection area or session context.\u003C\u002Fp>\n\u003Cp>Partial credit card data is the area of this record that should be explained most carefully. This information alone should not be considered sufficient to initiate a card payment; the verified list does not include the card's expiration date or CVC code. Nevertheless, when name, phone, email, and partial card information are combined, the risk of social engineering increases. A fraudster may reference parts of the card or a campaign membership to gain the user's trust.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified scope consists of 89,388 affected accounts, a breach date of August 20, 2019, an addition date of September 1, 2019, and six types of data: email addresses, IP addresses, names, partial credit card data, phone numbers, and salutations. The record is associated with the Mastercard Priceless Specials program in Germany. It is understood that the program was suspended after the incident and that the related domain name no longer appears to be accessible without issues.\u003C\u002Fp>\n\u003Cp>This record should not be described as a leak of a password, bank account, CVC code, or card expiration date. Partial card data carries financial risk, but does not imply full payment authorization. Although some news mentions wider record fields, the data class list visible to the user on this page should be limited to verified query records. The main risks to be conveyed to the user are phishing, phone scams, card support line impersonation, profile matching, and loss of privacy.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Users at the highest risk are those who use the same email and phone information in their Priceless Specials membership as in their banking, card, shopping, or rewards program accounts. Fraudsters may send fake campaign points, card security checks, suspicious transaction alerts, or account verification messages using the name of Mastercard or the issuing bank. The name and salutation information make it easier for these messages to appear as genuine customer communication.\u003C\u002Fp>\n\u003Cp>Users with partial card information should also evaluate every communication from the card provider more carefully. Even if the leaked information does not show the full card, it can be used to gain trust during a phone call. The risk of targeted messages also increases for users with an IP address and email address. Therefore, both the email inbox, phone messages, and customer service calls related to the card should be checked separately.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If you see a match in this record, first identify your affected email address and the card linked to your Mastercard Priceless Specials membership. Check card transactions and security notifications from your card provider. If you notice an unknown transaction, unexpected limit change, suspicious card verification request, or a rewards program message, start a separate session through your card provider's official channel. Do not click directly on any links in the message.\u003C\u002Fp>\n\u003Cp>Do not share your full card number, CVC code, one-time verification code, or online banking information during phone calls. Enable two-step verification on your email account and check your recovery options. Carefully examine the sender's domain and the type of information requested in campaign, refund, reward points, and security check messages coming under the name of Priceless Specials or Mastercard. A message containing partially correct information should not be assumed to be legitimate.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>For long-term protection, financial loyalty programs, shopping campaigns, and card accounts should be monitored with separate security habits. The main email address should be protected for critical banking and card transactions, and a separate email address can be preferred for campaign and reward memberships. Transaction notifications, spending limits, and suspicious transaction alerts from your card provider should be kept active. Regularly reviewing programs where you share your phone number also reduces the risk of smishing.\u003C\u002Fp>\n\u003Cp>Old loyalty program accounts should not be forgotten. Unused memberships should be closed, and unnecessary personal information on open accounts should be reduced. Partial card data, phone numbers, and email addresses can be used in fake customer service scenarios even years later. Therefore, old breaches like those of Mastercard Priceless Specials should not be seen as limited to a one-time check; monitoring card activity, email security, and awareness of phone fraud should be made permanent.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If you notice a match in the Mastercard Priceless Specials breach, first note your affected email address, phone number, and the card associated with this membership. Then check your transaction history, security alerts, and card notifications through your card provider's official channel. Strengthen the security settings of your email account, log out of unknown sessions, and update recovery options. Due to the risk of social engineering, do not provide information immediately to any call requesting card details.\u003C\u002Fp>\n\u003Cp>This record should not be treated as a password or full card payment information leak; the verified risk comes from a combination of email, IP address, name, salutation, phone number, and partial card data. Although the breach dates back to 2019, this information can still be used today in fake messages themed around campaigns, card security, and reward programs. The most appropriate action is to monitor card activity, secure the email account strongly, and separately verify any personal information requests that come in the name of Mastercard or the bank through official channels.\u003C\u002Fp>","","Mastercard Priceless Specials Data Breach (89.4 Thousand Reported Records)","Mastercard Priceless Specials Data Breach. 89.4 Thousand reported records were reported. Reported data: Email addresses, IP addresses, Names. Review the…","\u002Fuploads\u002Flogo\u002Fspecials_mastercard_de.webp",false,{"name":38,"sector":39,"country":40,"website":10,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":21},"Mastercard Priceless Specials","Financial Services \u002F Loyalty Program","Germany"]