Skip to content

Twelve Databases Leaked in Single Dump, 14,453 Customer Records From WordPress Sites Exposed

Breach Report Multi-Region WordPress / E-commerce Free Download

Twelve Databases Leaked in Single Dump, 14,453 Customer Records From WordPress Sites Exposed

A forum user posting as NightBroker has published 12 databases in a single release, claiming the sites were located through search engine reconnaissance and required minimal effort to access. The dump holds 14,453 customer records across eleven small businesses and organisations, plus a twelfth file listing 216,470 usernames from a language-learning platform with no further personal data attached. Column structures identify every affected site as running WordPress with the WooCommerce store plugin. Exposed fields include names, emails, phone numbers, full billing and shipping addresses, order history, payment processor references, session tokens with IP addresses, and password hashes in WordPress's legacy format. The claim is unverified.

Customer records14,453
Databases12
PriceFree
ActorNightBroker

Post details

Targets12 unrelated sites
RegionsIE, ZA, NZ, DE, TR, IN, AT, US
SectorSmall business e-commerce
ListingFree — points to unlock
Records14,453 + 216,470 usernames
PlatformWordPress / WooCommerce
Observed
ActorNightBroker

!Sites affected

  • tatoeba.org — 216,470
  • bodygraphicstattoosupply.co.za — 3,257
  • ferminiatures.com — 3,257
  • sahabatgenpro.com — 2,777
  • mesa.com.tr — 1,978
  • blusheshairsalon.com — 1,052
  • skifederation.org — 906
  • willrich.com — 271
  • weingut-topf.at — 144
  • museumtrade.org — 96
  • webcomsystems.in — 57
  • knoxfocus.com — 12

Screenshots

Potential impact

The password hashes are the material concern. WordPress's legacy hashing scheme, visible throughout the samples, is far weaker than modern alternatives and crackable at scale, so recovered passwords will unlock any other account where a customer reused them. Beyond that the records carry home addresses, phone numbers, and order history, and the session data embeds IP addresses and device details, allowing rough location and device profiling. The headline 216,470 figure is usernames only and carries little sensitivity. The wider point is the pattern: these are small businesses without security staff, found in bulk, and unlikely to notify anyone.

iStatus

Unverified

Samples and full column listings are published for three of the twelve, and the schemas are internally consistent with genuine WordPress exports rather than assembled lists. The actor states these were incidental finds outside their usual focus, and published the collection without payment. The account is established with moderate standing. Nothing has been independently corroborated. The claim is unverified and none of the affected sites has publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest