[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f32128fr66x52b":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":28,"seoTitle":15,"seoTitleEn":29,"seoDescription":15,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda48825303","pandabuy","Pandabuy Data Breach","pandabuy.com","2024-03-31T00:00:00.000Z","2024-04-01T08:34:24.000Z","2026-07-03T14:58:02.905Z","2026-07-18T23:55:42.098Z","Third party breach","",[],1348407,"known",null,"unknown","Critical",[23,24,25,26,27],"Email addresses","IP addresses","Names","Phone numbers","Physical addresses","\u003Cp>Pandabuy data breach is a customer data incident dated March 2024 associated with China-based shopping proxy Pandabuy. The record contains 1,348,407 unique email addresses. Data classes include email addresses, IP addresses, names, phone numbers, and physical addresses. Some reports have also mentioned order inquiries and shipping context; therefore, cargo and payment redirection frauds should be particularly considered.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>When email, name, phone, physical address, and IP address are found together, a shopping profile belonging to the user can be strongly identified. In cross-border shopping flows like Pandabuy, users are accustomed to package, customs, warehouse, return, and payment update messages.\u003C\u002Fp>\u003Cp>When fields such as name, email, phone, address, username, or location come together, attackers can prepare messages that appear as if the user has a real service relationship. This information alone does not always mean account takeover; however, it can be used for phishing, fake support requests, delivery notifications, account verification, and personalized scam flows. The record does not list password or full payment card fields. Nevertheless, address and phone fields can be used for fake shipping, customs fees, warehouse charges, or return links. The IP address can also provide credibility when sending the user technical security alerts.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The incident date is recorded as March 31, 2024, with the number of affected emails being 1,348,407. Reliable security news reports that the data was shared on a forum, including fields such as IP and physical addresses, names, phone numbers, and order queries. The current data classes are compatible with this scope.\u003C\u002Fp>\u003Cp>When explaining the scope, it should not be said that every user's full order details or payment information are exposed. The correct risk is the combination of shopping and delivery context with contact information. The user should verify messages, especially those related to shipping and customs, through a separate channel.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Users at risk are those who have opened an account, placed an order, or shared a warehouse or shipping address through Pandabuy. Since people who shop internationally are accustomed to customs, shipping, and payment messages, targeted attacks may be more successful.\u003C\u002Fp>\u003Cp>Users with up-to-date phone and address information can be targeted through SMS, email, and call channels. The IP address can be used in fake security or session notification messages. People who share Pandabuy purchases in social media communities may also carry the risk of profile matching.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Matched users should check that they are using a unique password on their Pandabuy account, and should change any shopping or payment accounts that use the same password. Messages regarding shipping, customs, warehouse fees, or returns should be verified through the official panel.\u003C\u002Fp>\u003Cp>Instead of opening incoming links directly, the user should log in through the known web address or official application of the relevant service. Knowing the caller's name, email, address, order, or profile information does not prove that they are trustworthy. One-time verification codes, payment card information, or account passwords should not be shared in any support conversation.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address on different platforms makes it easier to combine data from different breaches; therefore, using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>In cross-border shopping accounts, old addresses, unused phones, and unnecessary order communications should be cleared. Users should track payment and shipping processes only from official accounts and should not trust support requests coming from social media connections.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is found in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset, and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result increases the risk of shopping and delivery themed fraud. A negative result means that there is no match within this record; the same email should be checked separately in other e-commerce records.\u003C\u002Fp>","Pandabuy Data Breach (1.3 Million Reported Records)","Pandabuy Data Breach. 1.3 Million reported records were reported. Reported data: Email addresses, IP addresses, Names. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fpandabuy_com.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Pandabuy","E-Commerce \u002F Shopping Agent","China"]