Skip to content

Generation Tux Dataset Claim Covers 2.8M+ Customer Records

Breach Report United States Customer & Credential Data 2.8M+ Customers

Generation Tux Dataset Claim Covers 2.8M+ Customer Records

A forum actor posting as seraphims is selling what they claim is a customer dataset belonging to Generation Tux, an online rental service for men's suits and tuxedos used for weddings, proms and other special events. The actor claims the company was breached in August 2026 through an authentication-bypass SQL injection exploit. The advertised dataset contains approximately 2.8 million unique customer records and includes names, email addresses, phone numbers, password hashes, Facebook IDs, ZIP codes, states, street addresses, cities and countries. The listing provides field-completeness statistics showing nearly all records contain names, emails and phone numbers, while roughly half include address information. The asking price is $2,000, negotiable. The claim is unverified.

Sponsored
Customers2.8M+
Passwords2.887M
Addresses~1.53M
Price$2,000

Post details

TargetGeneration Tux
CountryUnited States
SectorApparel rental / e-commerce
ListingCustomer dataset for sale
Volume2.8M+ customers
Claimed intrusionAuth bypass / SQLi
Observed
Actorseraphims

!What the post claims

  • Approximately 2.8M unique customer records
  • 2,889,599 names
  • 2,889,599 email addresses
  • 2,889,599 phone numbers
  • 2,887,679 password hashes
  • 5,868 Facebook IDs
  • 1,557,949 ZIP codes
  • 1,502,326 state values
  • 1,534,543 primary street addresses
  • 15,397 secondary address values
  • 1,534,543 city values
  • 1,534,544 country values
  • Claimed August 2026 breach
  • Authentication bypass claimed
  • SQL injection claimed
  • Dataset offered for $2,000
  • Price listed as negotiable

Screenshot

Forum post offering an alleged Generation Tux customer dataset containing identity, contact, address and password-hash data, observed 16 September 2026.

Mapped techniques

The techniques below are based on the intrusion method and dataset contents described by the actor. Dark Web Informer has not independently verified the attack chain.

  • Initial Access T1190 Exploit Public-Facing Application Claimed The actor claims Generation Tux was compromised through an authentication-bypass SQL injection vulnerability affecting a public-facing application.
  • Collection T1213 Data from Information Repositories Claimed The listing describes a structured customer dataset containing identity, contact, account and address fields, consistent with collection from an application database.

Potential impact

If authentic, the dataset could expose millions of customers to credential stuffing, phishing, account takeover attempts and identity-based fraud. Even though the passwords are described as hashes rather than plaintext, weak or reused passwords could still create risk if any hashes are cracked. The combination of names, email addresses, phone numbers and physical addresses gives attackers enough context to build convincing impersonation and delivery-themed scams, while the scale of the dataset increases the likelihood of automated abuse across other services.

iStatus Unverified

The forum listing includes a sample, field-completeness statistics and a specific intrusion claim involving authentication bypass and SQL injection. However, it does not provide independently verifiable evidence of how the vulnerability worked, whether the alleged weakness has been remediated or whether the full dataset originated directly from Generation Tux. Dark Web Informer has not independently verified the breach, the 2.8 million-record count or the authenticity of the advertised customer data.

Dark Web Informer // Threat Intelligence

Latest