Skip to content

Wrappiness Customer Database Allegedly Offered for Sale With 3 Million Order Records

Breach Report United States flagUnited States E-commerce / Personalised Gifts $2,000 USD

Wrappiness Customer Database Allegedly Offered for Sale With 3 Million Order Records

A forum user posting as Satanic is selling what they describe as the full database of Wrappiness.co, a United States retailer of personalised and custom gifts including wood signs, ornaments and keychains. The listing claims three million user records and 115 administrator accounts, and dates the intrusion to August 18, 2026, two days before posting. Published field lists show order records carrying names, email addresses, phone numbers and full billing and shipping addresses, alongside purchase values, carrier tracking numbers and the personalisation details attached to each item. Administrator records include hashed passwords and permission sets. The asking price is $2,000. The claim is unverified.

User records3M
Admin accounts115
Asking price$2,000
ActorSatanic

Post details

TargetWrappiness.co
CountryUnited States flagUnited States
SectorCustom gift retail
ListingSelling, escrow accepted
Volume3M users, 115 admins
Breach dateStated as Aug 18, 2026
Observed
ActorSatanic

!Allegedly included

  • Customer full names
  • Email addresses
  • Phone numbers
  • Full shipping addresses
  • Billing addresses
  • Company names
  • Order values and costs
  • Purchased item details
  • Personalisation content
  • Uploaded photo references
  • Carrier tracking numbers
  • Referring social profiles
  • Platform risk scores
  • Admin hashes and permissions

Screenshots

Potential impact

No card numbers appear in the published schema, and administrator passwords are stored as bcrypt hashes rather than in the clear, which limits the worst outcomes. What remains is a large and unusually descriptive consumer set. Each record reportedly ties a named person to a home address, phone number and email, plus what they bought and who they bought it for. Personalised goods make that last part meaningful, because the customisation text and uploaded images can reveal family names, pets, dates and relationships that ordinary retail orders do not. That supports convincing delivery and order confirmation scams, since an attacker can cite a real item, a real tracking number and a real recipient. The administrator set is the operational concern: 115 accounts with defined permissions and last seen timestamps would give an attacker a map of internal roles even if the hashes hold.

iStatus

Unverified

The evidence is stronger than a bare claim: the seller publishes complete field lists for both collections and record samples that match them, and the structure is consistent with an order management layer sitting over a storefront platform rather than the storefront itself. The three million figure is the seller's own and is not broken down between orders and unique customers, which matters for a retailer where repeat purchases are common, so the number of distinct people affected may be materially lower. The same account offered a separate collection of merchant payment data days earlier. Dark Web Informer is not reproducing the samples, which contain complete customer identities, nor the contact route. The claim is unverified and the retailer has not publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest