Skip to content

Taiseer (taiseer.co) Database Breached: Threat Actor Sorb Offering PII of Egyptian Gold Investors for Sale

Active Threat Report ID: DWI-2026-0420-25
Threat Intelligence Report

Taiseer (taiseer.co) Database Breached: Threat Actor Sorb Offering PII of Egyptian Gold Investors for Sale

A threat actor operating under the alias Sorb is selling the database of Taiseer (taiseer.co), the Egyptian Sharia-compliant fractional gold-savings fintech. The listing claims 71,000 user records with full names, emails, phone numbers, bcrypt password hashes, addresses, gold balances, and 27,000 national ID card records with scanned front-and-back images — offered for $400 with escrow.

Published
Origin Egypt
Sector Fintech / Gold Investment
Read Time 6 min
Critical Severity

71,000 investor records from Egypt's Sharia-compliant fractional gold-savings platform, including bcrypt password hashes, 27,000 national ID scans, and per-user gold balances. The seller also claims continued access to the environment. High risk of account takeover, identity theft, and targeted fraud against high-balance holders.

01

Incident Summary

Date & Time2026-04-20 21:54 UTC
Threat ActorSorb
VictimTaiseer (taiseer.co)
IndustryFintech / Gold Investment
CategoryData Breach
Total Users71,000
ID Cards27,000
Unique Emails71,000
Unique Phones71,000
Price$400 USD
EscrowYes
AccessOngoing
Forumspear.cx
Contactt.me/sorblines
NetworkOpen Web
Country Egypt
02

Incident Overview

A threat actor going by Sorb is selling a database attributed to Taiseer (taiseer.co), a Cairo-based fintech founded in 2023 and headquartered at the Nile University campus. Taiseer operates a Sharia-compliant mobile app that lets Egyptian savers buy investment-grade gold in fractions, describing itself in its own marketing as "the first digital platform for saving in gold."

According to the post, the dataset contains 71,000 user records with 71,000 unique emails, 71,000 unique phone numbers, and 27,000 unique national ID card records. Sample rows published by the actor confirm the following schema and data categories:

  • Core Account DataFull names (in Arabic script), email addresses, Egyptian mobile numbers (002012 prefix), bcrypt password hashes, and Firebase Cloud Messaging (FCM) push tokens tied to individual devices.
  • KYC Identity RecordsEgyptian national ID numbers (14-digit format), ID photo front and back filenames, nationality, residence country, and city — 27,000 verified identities in total.
  • Demographic DataGender, date of birth (sample DOBs span 1947–1999), job title (Marketing Consultant, Product Designer, banker, engineer, graphic designer, application designer, among others), and home address.
  • Financial & Gold BalancesCurrent gold balances, out-balance, current and reserved gold shares, referral data, transaction history, and account timestamps for created_at and updated_at events.
  • Administrative FlagsAdmin verification status, rejection reasons, basic-info flags, and referral link IDs — the internal fields a full database dump would expose to a buyer attempting to identify high-value or recently onboarded accounts.

The listing is priced at $400 USD with escrow available, and the actor notes that buyer access "does not affect the price" — language that the seller interprets as indicating ongoing or retained access to the source environment rather than a one-off dump. The actor directs interested buyers to t.me/sorblines for contact and advertises a broader data-leak channel at t.me/totaldataleaks. The combination of bcrypt password hashes, scanned national ID cards, and per-user gold balances is the most damaging element: it pairs an account takeover vector (via hash cracking or credential stuffing against other services) with verified identity documents suitable for KYC-bypass fraud, and a known target value in physical gold. For a platform of Taiseer's size, this represents effectively the entire customer base.

03

Compromised Data Categories

Full Names Email Addresses Phone Numbers Bcrypt Password Hashes National ID Numbers ID Photo Scans (Front/Back) Home Addresses Date of Birth Gender Job Titles Gold Balances Gold Shares Transaction History FCM Push Tokens Referral Data
04

Screenshots

Sorb forum listing header titled EGYPT TAISEER.CO GOLD INVESTORS with Taiseer homepage screenshot
FIG 01 · spear.cx listing header and seller profile (Sorb, Leaksmaster)
Listing details: 71,000 users, 27,000 ID cards, bcrypt hashes, address, job, balances — priced at $400 with escrow
FIG 02 · Listing body — volumes, field list, $400 price, escrow, Telegram contact
Sample KYC table from leak with id_number, address, job, gender, date_of_birth, nationality, id_photo_front, id_photo_back fields
FIG 03 · KYC/ID-verification sample — id_number, job, gender, DOB, photo filenames
Sample users table with bcrypt password hashes, FCM tokens, current_balance, current_gold_shares, and admin verification flags
FIG 04 · Users table sample — bcrypt hashes, FCM tokens, gold shares, admin flags

This post is for subscribers on the Plus, Pro and Elite tiers

Subscribe

Already have an account? Sign In

Latest