> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Alleged Pet Stop Dataset With 1M+ Records Offered for $140
- URL: https://darkwebinformer.com/alleged-pet-stop-dataset-with-1m-records-offered-for-140/
- Published: 2026-09-24T16:06:21.000Z
- Updated: 2026-09-24T16:06:21.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Data Exposure Report United States Dataset Sale Personal Data $140 Unverified 

## Alleged Pet Stop Dataset With 1M+ Records Offered for $140

Claimed unique lines1M+

Asking price in USD$140

Named data fields7

Payment requestedXMR

Severity HIGH 

### Overview

An actor using the handle **"Spaniard"** claims to have breached **Pet Stop** and is offering an alleged dataset containing **more than one million unique lines** for **$140, payable in Monero (XMR)**. The post identifies the target as petstop.com and describes it as a US-based manufacturer of pet products.

The actor claims the dataset includes **email addresses, passwords, names, cities, states, countries and ZIP codes**. The listing specifies escrow and XMR-only payment and refers buyers to a qTox contact in the actor's signature. A sample-data URL is shown in the source and blurred in this report's screenshot. **The alleged breach, dataset authenticity, record count and password format have not been independently verified.**

### Post details

OrganizationPet Stop

Country United States

SectorPet products

Actor"Spaniard"

Claimed volumeMore than 1 million unique lines

Asking price$140, payable in XMR

Transaction termsEscrow; XMR only

Post date shownSep 24, 2026

### What the post claims

- Breach of Pet Stop claimed
- More than 1 million unique lines claimed
- Email addresses
- Passwords, with storage format unspecified
- Names
- Cities and states
- Countries and ZIP codes
- $140 asking price, payable in Monero
- Escrow and XMR-only payment terms

Sponsored

[ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel)

### Screenshots

[Screenshot 1Redacted preview![Pet Stop dataset sale claim advertising more than one million lines for $140 in Monero, with the sample-data URL blurred](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/67867832958796235987629387659867232892.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/67867832958796235987629387659867232892.png) 

Screenshot of the listing showing the claimed dataset size, data categories, asking price and payment terms. The sample-data URL has been blurred.

### IOCs & contact identifiers

Identifiers visible in the source material. The actor handle supports correlation and does not, on its own, establish compromise.

| Type                      | Identifier      | Source       |
| ------------------------- | --------------- | ------------ |
| Actor handle              | Spaniard        | Screenshot 1 |
| Named organization domain | petstop\[.\]com | Screenshot 1 |

The domain identifies the organization named in the claim, not malicious infrastructure. The post mentions qTox, but no Tox ID is visible in the supplied screenshot. No Telegram handle, Session ID, malware hash or attacker-controlled IP address is visible. The sample-data URL is omitted from this table. URLs to any data will always be blurred out, but are available to subscribers on the threat feed or ransomware feed.

### Mapped techniques

No MITRE ATT&CK technique is assigned from this screenshot alone. The actor claims a breach and offers data for sale but does not establish an initial-access vector, collection method or exfiltration mechanism. The reference to passwords does not show credential dumping, password cracking or the format in which those passwords are stored.

### Potential impact

If authentic, the claimed combination of **names, email addresses and location fields** could support targeted phishing, impersonation and profiling. Exposure of usable passwords could create account-takeover risk, including on other services where the same credentials are reused. The listing does not establish whether the alleged passwords are plaintext, hashed or otherwise protected. **More than one million lines does not establish one million distinct affected people.**

### Status Unverified

Dark Web Informer has **not independently verified** the alleged breach, the actor's access, dataset ownership, record count or data accuracy. The screenshot contains an advertisement and a sample link, but no sample records are displayed. The linked sample was not accessed for this report. The source does not establish the age of the records, whether the dataset is new or recycled, or whether it contains duplicate identities. No company confirmation or technical evidence of the intrusion is included.

Want everything on this threat? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=pet-stop-dataset-sale-2026-09-24&utm%5Fcontent=threat-feed) and search there for this alert.

[View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=pet-stop-dataset-sale-2026-09-24&utm%5Fcontent=pricing-button) 

[Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=pet-stop-dataset-sale-2026-09-24&utm%5Fcontent=footer)