Skip to content

Saudi Automotive Marketplace Speero Allegedly Dumped in Full, Including Password and Reset Token Fields

Breach Report Saudi Arabia flagSaudi Arabia E-commerce / Automotive Parts Price On Request

Saudi Automotive Marketplace Speero Allegedly Dumped in Full, Including Password and Reset Token Fields

A newly registered user posting as UNC2030 is offering what they describe as a complete dump of speero.net, a Riyadh based marketplace for car parts and maintenance services, comprising 83 tables and 11GB of CSV data. The user table alone is listed at 1,000,034 rows, and its published column list includes a password field alongside email verification tokens, password reset codes and one time account restoration tokens. Other tables cover addresses, wallet balances and transactions, invoices, payment captures and messaging logs. The seller has posted a free sample of the user table and is offering lookups on request. The claim is unverified.

User rows1,000,034
Tables83
Volume11GB
ActorUNC2030

Post details

Targetspeero.net
CountrySaudi Arabia flagSaudi Arabia
SectorCar parts marketplace
ListingSelling, price on request
Volume11GB, 83 CSV tables
SamplesUser table posted free
Observed
ActorUNC2030, new account

!Allegedly included

  • Customer full names
  • Email addresses
  • Mobile phone numbers
  • Stored password field
  • Email verification tokens
  • Password reset OTP fields
  • Account restoration tokens
  • Push notification tokens
  • Delivery addresses
  • Wallet balances
  • Wallet transaction history
  • Invoices and orders
  • Payment capture records
  • Lifetime spend and margin

Screenshots

Potential impact

The token columns are the most pressing element. A password field of unknown format is one problem, but email verification tokens, password reset codes and one time restoration tokens can permit account takeover without touching the password at all if any remain unexpired, and the restoration tokens in particular are designed to reverse a deletion request. Around a million customers are reportedly exposed with names, emails, mobile numbers and delivery addresses, which in a market where transactions run heavily through mobile messaging makes convincing fraud straightforward. Two further details raise the stakes: wallet balances and transaction history let an attacker rank accounts by the value sitting in them, and per customer lifetime spend and margin fields do the same commercially. Card tables appear small at a few hundred rows, so mass card exposure looks unlikely on the published counts.

iStatus

Unverified

The seller has no track record whatsoever, having registered this month with a single post, which is the weakest standing of any actor in this series of listings. Against that, the evidence offered is more granular than most: a full table inventory with per file row counts and sizes that are internally consistent, plus a free sample of the user table. What the post does not establish is how passwords are stored, and the column list alone cannot distinguish a modern hash from something weaker. The offer of lookups on request extends the harm to named individuals even for those who never buy the set. Dark Web Informer is not reproducing the sample link or the contact identity. The claim is unverified and Speero has not publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest