[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fh2t1kwv9b3hi":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":23,"affectedCountUnit":24,"hasEnglishDescription":4,"severity":25,"dataClasses":26,"description":34,"seoTitle":35,"seoTitleEn":36,"seoDescription":35,"seoDescriptionEn":37,"logoUrl":38,"isVerified":4,"isSensitive":39,"isSpamList":39,"isMalware":39,"company":40},"68e3266eda11adda48825375","ShopBack","ShopBack Data Breach","shopback","shopback.com","2020-09-17T00:00:00.000Z","2021-04-25T05:41:24.000Z","2026-07-19T19:25:02.268Z","Verified regulatory breach","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20210425054426\u002Fhttps:\u002F\u002Fsupport.shopback.com.au\u002Fhc\u002Fen-us\u002Farticles\u002F360054141274-Customer-Notice-FAQs",[15,17,18,19,20],"https:\u002F\u002Fwww.marketing-interactive.com\u002Fshopback-fined-sg74400-after-personal-data-leak-affecting-millions-of-customers","https:\u002F\u002Fwww.straitstimes.com\u002Fsingapore\u002Fshopback-fined-74400-over-data-leak-that-affected-more-than-14-million-users","https:\u002F\u002Fcorporate.shopback.com\u002Fabout","https:\u002F\u002Fstatic-common.shopback.com\u002Fimages\u002Flogo-black.svg",20529819,"known",null,"unknown","Critical",[27,28,29,30,31,32,33],"Bank account numbers","Email addresses","Geographic locations","Names","Partial credit card data","Passwords","Phone numbers","\u003Cp>\u003Cstrong>The ShopBack data breach\u003C\u002Fstrong> exposed identity, contact and password data linked to 20,529,819 email accounts in September 2020.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The ShopBack incident exposed email addresses, country or geographic-location data, names, phone numbers and password hashes. A regulatory investigation also confirmed that the Singapore scope included about 300,000 bank account numbers and partial credit-card data for roughly 380,000 people. Passwords were salted SHA-1 hashes rather than plain text. Salting slows attacks, but SHA-1 does not make weak passwords safe. Email, name, phone and country data can personalise fake refund, cashback-withdrawal or account-verification messages. Bank-account and partial-card information is insufficient for a direct transaction but may help a scammer gain trust. Full card numbers, security codes, cashback balances, dates of birth, genders and detailed purchase histories are not confirmed structured classes. The financial fields were confirmed in the regional investigation and should not be assumed to apply to every global record.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The incident began when a full-privilege cloud access key was accidentally saved to a private source-code repository in June 2019. It was removed from the visible file but remained in change history and was not fully disabled during rotation. About 15 months later, on 9 September 2020, an attacker used it to enter the cloud environment, alter security settings and extract customer records. ShopBack detected the access during a routine review on 17 September; this remains the canonical breach date while 9 September is recorded as the attack date. The company deleted the key, rotated access and forced all customers to sign out and reset passwords. The database was offered for sale on 12 November. The 20,529,819 figure is the global unique-email count; the regulatory figure above 1.4 million covers Singapore and must not be added to it. This distinction prevents regional counts from inflating the global record total.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People who created a ShopBack account before 2020 and supplied an email, phone number or country are the primary risk group. Anyone who reused the ShopBack password on email, shopping, travel or financial services faces a higher account-takeover risk. The Singapore review found about 1.4 million email addresses, 840,000 names, 450,000 mobile numbers, 300,000 bank accounts and 380,000 partial-card records; not every person should be assumed to have every field. Email, phone and a cashback relationship can support fake balance, withdrawal, refund or promotion messages. Partial financial details may make impersonation calls appear to come from a bank or card issuer. Abandoning the account does not erase the risk because contact details and reused passwords may remain valid for years. Record completeness varies, so an email match alone does not prove that every listed field was exposed for that person.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>\u003Cstrong>If you have not changed your ShopBack password since 2020, replace it now with a long, unique password.\u003C\u002Fstrong> Change similar credentials on other accounts, beginning with primary email, shopping and financial services. Open reset from the app or an official address you type yourself rather than a link in an unexpected message. Close active sessions, verify recovery email and phone details, and enable multi-factor authentication where available. Customers who supplied bank or card information should monitor account activity and alerts, contacting the financial institution through its official channel if an unfamiliar transaction appears. Never provide a password, one-time code, full card number or security code to a message claiming to concern cashback, withdrawal, refund or promotion activity.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>A password manager that generates a different credential for every service prevents one old hash from unlocking other accounts. Because email controls recovery for financial and shopping services, protect it with your strongest password and a resilient second factor such as an authenticator app or security key. Enable bank and card notifications, investigate even small test charges, and review recovery information regularly. Close shopping accounts you no longer use and avoid retaining optional phone, location or payment details. Breach monitoring, session reviews and phishing awareness provide lasting protection. Treat targeted messages seriously even years later because stolen datasets may be copied, resold and combined with newer information.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>\u003Cstrong>Check your email address with LeakData\u003C\u002Fstrong> to see whether it matches ShopBack or another verified breach. A match places the address among the canonical 20,529,819 unique emails; it does not prove that you were in the 1.4-million-person Singapore subset or that bank and partial-card fields belong to you. Review the date and classes, consider where you reused your 2020 password, and start with accounts controlling email and money. Never enter a password, bank account number or card information into the search field; an email address is sufficient. Ongoing monitoring can flag data published or recirculated later. Continue unique passwords, multi-factor authentication and transaction alerts even when no match appears.\u003C\u002Fp>","","ShopBack Data Breach (20.5 Million Reported Records)","ShopBack Data Breach. 20.5 Million reported records were reported. Reported data: Bank account numbers, Email addresses, Geographic locations. Review the…","\u002Fuploads\u002Flogo\u002Fshopback-official.svg",false,{"name":41,"sector":42,"country":43,"website":10,"websiteArchiveUrl":35,"websiteStatus":35,"websiteCheckedAt":23},"ShopBack Pte. Ltd.","E-commerce","Singapore"]