South Korea
Food Delivery / Cloud Misconfiguration
$60,000 USD
Korean Delivery Platform FLY Allegedly Dumped in Full After Backend Left Open to Anonymous Write Access
A forum user posting as exfilar is offering what they describe as a complete live extraction of the production backend behind flyfly.co.kr, a Korean food-delivery platform, listed at 47.9 million rows across 46.6GB and priced at $60,000 in Monero. The seller states the project's Firebase rules were absent entirely, leaving Firestore and Cloud Storage readable and writable without authentication. The claimed contents include resident registration numbers with plaintext passwords for 11,629 delivery riders, 6.16 million orders carrying customer GPS coordinates and apartment entry codes, and payment-gateway keys for thousands of restaurants. The listing is dated hours after the newest records it contains. The claim is unverified.
▣Post details
South Korea!Allegedly included
- Resident registration numbers
- Plaintext account passwords
- Bank names and account numbers
- Rider licence numbers
- Live rider GPS positions
- Customer names and phones
- Home addresses to unit level
- Building entry codes
- Payment gateway API keys
- Card terminal credentials
- Store owner identity records
- Push tokens and device IDs
- IP-linked access logs
- Delivery proof photographs
◱Screenshots
⚠Potential impact
If the listing is accurate, this is a near-total exposure of everyone the platform touches. Riders are worst affected: their records reportedly pair the Korean resident registration number, used for identity verification nationwide, with a plaintext password and a bank account in the same document. Customers appear across 6.16 million orders combining name, phone, address, precise coordinates, and, where delivery instructions were saved, the code that opens the building door, which carries physical-safety implications well beyond ordinary fraud. The claimed payment-gateway keys and card terminal credentials for thousands of restaurants would put transaction infrastructure at risk, not just records about it. Most consequential is the claimed write access: a writable backend means records could be altered or payment details redirected, and the exposure stays live until the rules are corrected and every credential is rotated.
iStatus
UnverifiedThe samples are internally consistent with a Firestore export and the field names match the structure of a Korean delivery platform, but consistency is not confirmation and the seller controls everything on display. Row counts, collection sizes, and pricing are the seller's own figures, and the valuation section reads as promotional. Dark Web Informer is not reproducing the sample link, the contact route, or any credential, identifier, or address appearing in the posted records. The account is recent, joined within the last two months, which is worth weighing against the scale of the claim. The claim is unverified and neither the platform operator nor Korean authorities have publicly addressed it.
DARK WEB INFORMER - THREAT INTELLIGENCE