[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f197e83qto4ifh":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":11,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":16,"affectedCount":16,"affectedCountStatus":17,"affectedCountLowerBound":18,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":31,"seoTitle":14,"seoTitleEn":32,"seoDescription":14,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":4,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda488253a9","tappware","Tappware Data Breach","tappware.com","2024-04-23T00:00:00.000Z","2024-05-09T00:34:12.000Z","2026-07-18T23:59:03.944Z","Third party breach","",[],94734,"known",null,"unknown","Medium",[22,23,24,25,26,27,28,29,30],"Dates of birth","Email addresses","Genders","Government issued IDs","Job titles","Names","Phone numbers","Physical addresses","Religions","\u003Cp>The Tappware data breach is a security incident recorded in April 2024, affecting approximately 95,000 accounts. In the incident associated with a Bangladesh-based IT service provider, business, identity, and demographic fields belonging to local citizens were exposed. This content has been prepared so that users can understand the scope of the incident, the fields that were leaked, the level of risk, and the steps to take, all on a single page.\u003C\u002Fp>\u003Cp>When fields such as official identity, religion, date of birth, address, and job title are combined, a profile that is much more sensitive than ordinary account data is formed. Only verifiable data classes are included in the description; different services with the same name, additional claims whose technical details have not been clarified, or information whose scope has not been proven are not presented as data fields. This approach makes the real risk visible without misleading the user.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data listed in this incident are: birth dates, email addresses, genders, official identification information, job titles, names, phone numbers, physical addresses, and religious beliefs. Fields such as official identification and religion increase the risk of discrimination, identity theft, and targeted fraud. When these fields are used together, they can lead to account takeover, social engineering, fraud, physical targeting, or privacy violations.\u003C\u002Fp>\u003Cp>In this record, the password field is not listed; however, since official ID and demographic fields are information that cannot be changed or are difficult to change, they carry long-term risk. One of the most critical risks in records containing passwords is the use of the same or similar password on other services. In records without passwords, fields such as device, location, phone, address, education, job application, or financial context can make targeted messages more convincing.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The record covers approximately 95,000 unique email addresses associated with the domain tappware.com. The incident is classified as a verified record. In the scope assessment, the number of accounts, domain, sector, country, and data classes were checked separately. The data fields shown to the user were limited to the fields actually listed in the record.\u003C\u002Fp>\u003Cp>The sector has been corrected in the context of Bangladesh IT services and workforce data instead of the government. This boundary is especially important for similar brand names, records covering multiple services, or sensitive sectors. The record has not been merged with another event, expanded in a way that would create duplicate records, and the company context has been clarified as much as possible.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Local citizens associated with Tappware, people with job applications or employment information, and users whose official ID area has been exposed are at risk. The main risk for these individuals is that the leaked fields can be matched with shared information used in other accounts. When the same email address, phone number, username, device ID, or password is repeated, attackers may try this information on different services.\u003C\u002Fp>\u003Cp>The context of work and identity can be used in fake public announcements, recruitment, bank verification, or document renewal messages. For corporate users, work email and job information are prominent, while for individual users, address, date of birth, purchases, location, or membership context stand out. In fields such as education, telecommunications, finance, travel, politics, job applications, and VPNs, the context itself can also increase targeting risk.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should carefully verify requests asking for official identification and phone information and check for suspicious activity in bank and public accounts. If a password or password-like field is listed, users should change it in all accounts where they use the same password, use a unique password, and enable multi-factor authentication where possible. Operating on just a single platform may not be sufficient.\u003C\u002Fp>\u003Cp>If there are fields such as phone, address, date of birth, device ID, official ID, job application, or reward balance, users should check account recovery information, registered sessions, email forwarding, and suspicious messages. For institutions, processes should be updated against employee alerts, fake invoices, and account verification attempts.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Long-term identity monitoring, document misuse control, and institutional notification processes are important in data incidents involving official identification. In the long term, password manager, unique passwords, multi-factor authentication, closing old accounts, deleting unnecessary profile fields, and data minimization form the basic security line. Since permanent personal data cannot be recovered, defense relies on strengthening account behavior.\u003C\u002Fp>\u003Cp>On the company and institutional side, post-incident inventory, access permissions, storage of old data, notification processes, and the use of third-party platforms should be reconsidered. On the user side, avoiding the repetition of the same identity information across different services and the habit of verifying suspicious communications through a second channel provide lasting protection.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If the user matches with this record, they should assess not only the email account but also the risks related to phone, official ID, and job application. If a match is observed, the user should first read which data fields are listed, then prioritize the steps according to these fields. If there is a password, change the password; if there is an official ID, track the ID; if there is location or device information, prioritize device security; if there is education or job application, prioritize checking the institutional account.\u003C\u002Fp>\u003Cp>Final assessment: This record is a high-impact personal data incident because it contains sensitive areas such as official identity and religious information. The user should compare this record with their account history; they should check the services where they use the same email, phone number, username, or password separately. Unexpected calls, messages, emails, or account recovery notifications should be considered higher risk after the incident.\u003C\u002Fp>","Tappware Data Breach (94.7 Thousand Reported Records)","Tappware Data Breach. 94.7 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Ftappware_com.webp",false,{"name":37,"sector":38,"country":39,"website":9,"websiteArchiveUrl":14,"websiteStatus":14,"websiteCheckedAt":18},"Tappware","IT Services \u002F Labour Data","Bangladesh"]