Skip to content

RevolutionParts Database Allegedly Leaked, 5.1 Million Customer Records Posted for Free

Breach Report United States flagUnited States Automotive / E-commerce Free Download

RevolutionParts Database Allegedly Leaked, 5.1 Million Customer Records Posted for Free

A forum user posting as kitta has published what they describe as the full database of RevolutionParts.com, the e-commerce platform used by automotive dealerships to sell parts online. The post claims the breach occurred in July 2026 and exposed 5,147,231 unique customers. The advertised field list combines conventional contact details with persistent device and browser identifiers, and a posted sample shows records carrying MD5-hashed email values alongside plaintext ones. The claim is unverified.

Records5,147,231
PriceFree
CountryUnited States flagUnited States
Actorkitta

Post details

TargetRevolutionParts.com
CountryUnited States flagUnited States
SectorAutomotive parts e-commerce
ListingFree — reply to unlock
Records5,147,231 unique customers
DataCustomer PII + device identifiers
Observed
Actorkitta

!Allegedly included

  • Full names
  • Email addresses
  • Phone numbers
  • Street addresses
  • City, state, ZIP
  • MD5-hashed emails
  • Browser IDs
  • Device IDs
  • Device brand & model
  • Device OS & version
  • MAC addresses
  • iOS advertising identifiers

Screenshot

Potential impact

No passwords or payment data appear in the advertised field list, which limits the immediate account-takeover risk. The more durable problem is the pairing of real identity with persistent device identifiers. Names, addresses, and phone numbers can at least be changed under duress; MAC addresses, device IDs, and advertising identifiers tie a named individual to specific hardware in a way that supports long-term tracking and cross-referencing against other leaked corpora. The presence of hashed emails and confidence scoring alongside sparse, unevenly populated fields suggests marketing enrichment or identity-resolution data rather than a clean transactional customer table, which would widen the question of whose data this actually is and how it was assembled. For affected individuals the near-term risk is targeted phishing: a caller who knows your name, address, phone, and the fact that you bought parts for a specific vehicle is credible in a way that generic fraud is not. Free distribution matters here too, since nothing has to be purchased for the set to circulate widely. The claim is unverified.

iStatus

Unverified

The account is recently registered with minimal posting history despite an elevated forum rank, and the download sits behind a reply gate, a common engagement-farming pattern that does not itself speak to authenticity either way. The record count and field structure have not been independently corroborated. The claim is unverified and RevolutionParts has not publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest