> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Twelve Databases Leaked in Single Dump, 14,453 Customer Records From WordPress Sites Exposed
- URL: https://darkwebinformer.com/twelve-databases-leaked-in-single-dump-14-453-customer-records-from-wordpress-sites-exposed/
- Published: 2026-08-05T17:01:30.000Z
- Updated: 2026-08-05T17:01:30.000Z
- Author: Dark Web Informer
- Tags: Leaks

Breach Report Multi-Region WordPress / E-commerce Free Download 

## Twelve Databases Leaked in Single Dump, 14,453 Customer Records From WordPress Sites Exposed

A forum user posting as **NightBroker** has published **12 databases** in a single release, claiming the sites were located through search engine reconnaissance and required minimal effort to access. The dump holds **14,453 customer records** across eleven small businesses and organisations, plus a twelfth file listing **216,470 usernames** from a language-learning platform with no further personal data attached. Column structures identify every affected site as running **WordPress with the WooCommerce store plugin**. Exposed fields include names, emails, phone numbers, **full billing and shipping addresses**, order history, payment processor references, session tokens with IP addresses, and **password hashes in WordPress's legacy format**. The claim is **unverified**.

Severity HIGH 

Customer records14,453

Databases12

PriceFree

ActorNightBroker

### ▣Post details

Targets12 unrelated sites

RegionsIE, ZA, NZ, DE, TR, IN, AT, US

SectorSmall business e-commerce

ListingFree — points to unlock

Records14,453 + 216,470 usernames

PlatformWordPress / WooCommerce

ObservedAug 5, 2026

ActorNightBroker

### !Sites affected

- tatoeba.org — 216,470
- bodygraphicstattoosupply.co.za — 3,257
- ferminiatures.com — 3,257
- sahabatgenpro.com — 2,777
- mesa.com.tr — 1,978
- blusheshairsalon.com — 1,052
- skifederation.org — 906
- willrich.com — 271
- weingut-topf.at — 144
- museumtrade.org — 96
- webcomsystems.in — 57
- knoxfocus.com — 12

### ◱Screenshots

[ ![Multi-leak of twelve WordPress databases forum post screenshot, August 2026 (1 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/432597823597862359867239876598723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/432597823597862359867239876598723.png) [ ![Multi-leak of twelve WordPress databases forum post screenshot, August 2026 (2 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/432597823597862359867239876598724.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/432597823597862359867239876598724.png) [ ![Multi-leak of twelve WordPress databases forum post screenshot, August 2026 (3 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/432597823597862359867239876598725.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/432597823597862359867239876598725.png) 

### ⚠Potential impact

The **password hashes are the material concern**. WordPress's legacy hashing scheme, visible throughout the samples, is **far weaker than modern alternatives and crackable at scale**, so recovered passwords will unlock any other account where a customer reused them. Beyond that the records carry **home addresses, phone numbers, and order history**, and the session data embeds IP addresses and device details, allowing rough location and device profiling. The headline 216,470 figure is **usernames only and carries little sensitivity**. The wider point is the pattern: these are small businesses without security staff, found in bulk, and **unlikely to notify anyone**.

### iStatus

Unverified 

Samples and full column listings are published for three of the twelve, and the **schemas are internally consistent with genuine WordPress exports** rather than assembled lists. The actor states these were incidental finds outside their usual focus, and published the collection without payment. The account is established with moderate standing. Nothing has been independently corroborated. The claim is **unverified** and none of the affected sites has publicly addressed it.

Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) 

[DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE