> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Saudi Automotive Marketplace Speero Allegedly Dumped in Full, Including Password and Reset Token Fields
- URL: https://darkwebinformer.com/saudi-automotive-marketplace-speero-allegedly-dumped-in-full-including-password-and-reset-token-fields/
- Published: 2026-08-21T16:55:24.000Z
- Updated: 2026-08-21T16:55:24.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Breach Report ![Saudi Arabia flag](https://flagcdn.com/w40/sa.png)Saudi Arabia E-commerce / Automotive Parts Price On Request 

## Saudi Automotive Marketplace Speero Allegedly Dumped in Full, Including Password and Reset Token Fields

A newly registered user posting as **UNC2030** is offering what they describe as a complete dump of **speero.net**, a Riyadh based marketplace for car parts and maintenance services, comprising **83 tables and 11GB of CSV data**. The user table alone is listed at **1,000,034 rows**, and its published column list includes a **password field alongside email verification tokens, password reset codes and one time account restoration tokens**. Other tables cover addresses, wallet balances and transactions, invoices, payment captures and messaging logs. The seller has posted a **free sample of the user table** and is offering lookups on request. The claim is **unverified**.

Severity CRITICAL 

[ ![WhiteIntel sponsor banner](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) 

User rows1,000,034

Tables83

Volume11GB

ActorUNC2030

### ▣Post details

Targetspeero.net

Country![Saudi Arabia flag](https://flagcdn.com/w40/sa.png)Saudi Arabia

SectorCar parts marketplace

ListingSelling, price on request

Volume11GB, 83 CSV tables

SamplesUser table posted free

ObservedAug 21, 2026

ActorUNC2030, new account

### !Allegedly included

- Customer full names
- Email addresses
- Mobile phone numbers
- Stored password field
- Email verification tokens
- Password reset OTP fields
- Account restoration tokens
- Push notification tokens
- Delivery addresses
- Wallet balances
- Wallet transaction history
- Invoices and orders
- Payment capture records
- Lifetime spend and margin

### ◱Screenshots

[ ![Speero Saudi Arabia automotive marketplace database sale forum post screenshot, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/923785278936587925897258976239871.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/923785278936587925897258976239871.png) [ ![Claimed table listing and row counts in the Speero dump](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/923785278936587925897258976239872.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/923785278936587925897258976239872.png) 

### ⚠Potential impact

The token columns are the most pressing element. A password field of unknown format is one problem, but **email verification tokens, password reset codes and one time restoration tokens can permit account takeover without touching the password at all** if any remain unexpired, and the restoration tokens in particular are designed to reverse a deletion request. Around a million customers are reportedly exposed with **names, emails, mobile numbers and delivery addresses**, which in a market where transactions run heavily through mobile messaging makes convincing fraud straightforward. Two further details raise the stakes: **wallet balances and transaction history** let an attacker rank accounts by the value sitting in them, and per customer lifetime spend and margin fields do the same commercially. Card tables appear small at a few hundred rows, so **mass card exposure looks unlikely** on the published counts.

### iStatus

Unverified 

The seller has **no track record whatsoever**, having registered this month with a single post, which is the weakest standing of any actor in this series of listings. Against that, the evidence offered is more granular than most: a full table inventory with per file row counts and sizes that are internally consistent, plus a free sample of the user table. What the post does not establish is **how passwords are stored**, and the column list alone cannot distinguish a modern hash from something weaker. The offer of **lookups on request extends the harm to named individuals** even for those who never buy the set. Dark Web Informer is **not reproducing the sample link or the contact identity**. The claim is **unverified** and Speero has not publicly addressed it.

Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) 

[DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE