Saudi Arabia
E-commerce / Automotive Parts
Price On Request
Saudi Automotive Marketplace Speero Allegedly Dumped in Full, Including Password and Reset Token Fields
A newly registered user posting as UNC2030 is offering what they describe as a complete dump of speero.net, a Riyadh based marketplace for car parts and maintenance services, comprising 83 tables and 11GB of CSV data. The user table alone is listed at 1,000,034 rows, and its published column list includes a password field alongside email verification tokens, password reset codes and one time account restoration tokens. Other tables cover addresses, wallet balances and transactions, invoices, payment captures and messaging logs. The seller has posted a free sample of the user table and is offering lookups on request. The claim is unverified.
▣Post details
Saudi Arabia!Allegedly included
- Customer full names
- Email addresses
- Mobile phone numbers
- Stored password field
- Email verification tokens
- Password reset OTP fields
- Account restoration tokens
- Push notification tokens
- Delivery addresses
- Wallet balances
- Wallet transaction history
- Invoices and orders
- Payment capture records
- Lifetime spend and margin
◱Screenshots
⚠Potential impact
The token columns are the most pressing element. A password field of unknown format is one problem, but email verification tokens, password reset codes and one time restoration tokens can permit account takeover without touching the password at all if any remain unexpired, and the restoration tokens in particular are designed to reverse a deletion request. Around a million customers are reportedly exposed with names, emails, mobile numbers and delivery addresses, which in a market where transactions run heavily through mobile messaging makes convincing fraud straightforward. Two further details raise the stakes: wallet balances and transaction history let an attacker rank accounts by the value sitting in them, and per customer lifetime spend and margin fields do the same commercially. Card tables appear small at a few hundred rows, so mass card exposure looks unlikely on the published counts.
iStatus
UnverifiedThe seller has no track record whatsoever, having registered this month with a single post, which is the weakest standing of any actor in this series of listings. Against that, the evidence offered is more granular than most: a full table inventory with per file row counts and sizes that are internally consistent, plus a free sample of the user table. What the post does not establish is how passwords are stored, and the column list alone cannot distinguish a modern hash from something weaker. The offer of lookups on request extends the harm to named individuals even for those who never buy the set. Dark Web Informer is not reproducing the sample link or the contact identity. The claim is unverified and Speero has not publicly addressed it.
DARK WEB INFORMER - THREAT INTELLIGENCE