Skip to content

Korean Delivery Platform FLY Allegedly Dumped in Full After Backend Left Open to Anonymous Write Access

Breach Report South Korea flagSouth Korea Food Delivery / Cloud Misconfiguration $60,000 USD

Korean Delivery Platform FLY Allegedly Dumped in Full After Backend Left Open to Anonymous Write Access

A forum user posting as exfilar is offering what they describe as a complete live extraction of the production backend behind flyfly.co.kr, a Korean food-delivery platform, listed at 47.9 million rows across 46.6GB and priced at $60,000 in Monero. The seller states the project's Firebase rules were absent entirely, leaving Firestore and Cloud Storage readable and writable without authentication. The claimed contents include resident registration numbers with plaintext passwords for 11,629 delivery riders, 6.16 million orders carrying customer GPS coordinates and apartment entry codes, and payment-gateway keys for thousands of restaurants. The listing is dated hours after the newest records it contains. The claim is unverified.

Volume46.6GB
Rows47.9M
Asking price$60,000
Actorexfilar

Post details

Targetflyfly.co.kr (FLY / 플라이)
CountrySouth Korea flagSouth Korea
SectorFood delivery logistics
ListingSelling, XMR preferred
Volume46.6GB, 47.9M rows, JSONL
Root causeClaimed absent Firebase rules
Observed
Actorexfilar

!Allegedly included

  • Resident registration numbers
  • Plaintext account passwords
  • Bank names and account numbers
  • Rider licence numbers
  • Live rider GPS positions
  • Customer names and phones
  • Home addresses to unit level
  • Building entry codes
  • Payment gateway API keys
  • Card terminal credentials
  • Store owner identity records
  • Push tokens and device IDs
  • IP-linked access logs
  • Delivery proof photographs

Screenshots

Potential impact

If the listing is accurate, this is a near-total exposure of everyone the platform touches. Riders are worst affected: their records reportedly pair the Korean resident registration number, used for identity verification nationwide, with a plaintext password and a bank account in the same document. Customers appear across 6.16 million orders combining name, phone, address, precise coordinates, and, where delivery instructions were saved, the code that opens the building door, which carries physical-safety implications well beyond ordinary fraud. The claimed payment-gateway keys and card terminal credentials for thousands of restaurants would put transaction infrastructure at risk, not just records about it. Most consequential is the claimed write access: a writable backend means records could be altered or payment details redirected, and the exposure stays live until the rules are corrected and every credential is rotated.

iStatus

Unverified

The samples are internally consistent with a Firestore export and the field names match the structure of a Korean delivery platform, but consistency is not confirmation and the seller controls everything on display. Row counts, collection sizes, and pricing are the seller's own figures, and the valuation section reads as promotional. Dark Web Informer is not reproducing the sample link, the contact route, or any credential, identifier, or address appearing in the posted records. The account is recent, joined within the last two months, which is worth weighing against the scale of the claim. The claim is unverified and neither the platform operator nor Korean authorities have publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest