LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Eye4Fraud Data Breach (2023)

CRITICAL severityConfirmedHow we verify

Eye4Fraud Data Breach (2023): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·January 25, 2023

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Eye4Fraud Data Breach (2023)

Reported January 25, 2023. Approximately 16.0M people affected.

CRITICAL
Severity
16.0M
People affected
7
Data types exposed
January 25, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Eye4Fraud Data Breach (2023) (reported January 25, 2023) exposed Email addresses, IP addresses, Names and Partial credit card data belonging to roughly 16.0M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Exposes financial data.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Eye4Fraud Data Breach (2023) breach?
16.0M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In early 2023, data alleged to have been taken from Eye4Fraud, a fraud-protection service, was listed for sale on a popular hacking forum. Public reporting associated with the incident cites roughly 16 million unique email addresses among tens of millions of rows of data, affecting both direct users of the service and people who had placed orders through other businesses that used Eye4Fraud to screen sales.

The material was described as spanning 147 tables and about 65 GB. Named data types include email addresses, IP addresses, names, partial credit card data, passwords, phone numbers, and physical addresses. The exact method of intrusion and full timeline remain limited in public detail, but the scale and the mix of personal and payment-related fields make the incident consequential for anyone whose information may have been included.

What happened

According to reporting tied to a January 25, 2023 disclosure date, data purportedly from Eye4Fraud appeared for sale on a popular hacking forum in February 2023. The listing described a large dataset: tens of millions of rows, 16 million unique email addresses, 147 tables, and a total size of approximately 65 GB. The data was said to cover both people who used Eye4Fraud directly and individuals who had ordered from other services that relied on Eye4Fraud for fraud protection.

Public accounts state that the material included names and bcrypt password hashes for users, along with names, phone numbers, physical addresses, and partial credit card data consisting of card type and last four digits. No public attribution to a specific threat group is given in the available facts, and details such as how the data was obtained, when the intrusion began, or whether every record is confirmed authentic are not fully established in the disclosed summary. The incident is therefore best understood as a large alleged exposure listed for sale, with the volume and field types reported as above.

How a breach like this happens

Incidents that end with large customer or transaction databases appearing on criminal forums often follow familiar patterns, even when the precise path into a particular organisation is undisclosed. Attackers may exploit unpatched software, weak or reused administrative credentials, misconfigured cloud storage or databases, or compromised third-party integrations. Once inside, they commonly copy large volumes of structured data—customer tables, order records, authentication stores—and later advertise the haul for sale or leak it to build reputation.

In fraud-prevention and e-commerce support systems, data often flows from many merchant partners into a central service. That concentration can mean a single compromise yields records belonging to people who never signed up with the service directly. Password data is frequently stored as hashes rather than plain text; bcrypt hashes, if present, are designed to slow guessing, but weak original passwords can still be cracked offline. Partial payment card fields and contact details are routinely retained for risk scoring and dispute handling, which is why they appear in many such dumps. None of this establishes the exact technique used against Eye4Fraud; it only describes how breaches of this general type typically unfold when method details are not public.

Eye4Fraud and its sector

Eye4Fraud operates in the fraud-protection sector, providing tools that help online merchants assess whether orders look legitimate or risky. Services of this kind typically receive order, identity, and sometimes payment-related signals from retailers so they can flag suspicious activity before goods ship or funds clear. Because the value of the service depends on pattern recognition across many transactions, such platforms often hold substantial volumes of personal and commercial data tied to buyers and to the merchants who integrate them.

A breach affecting a fraud-protection provider is consequential for two reasons. First, the population at risk can extend well beyond the provider’s own account holders to customers of every merchant that fed data into the system. Second, the same fields useful for stopping fraud—names, addresses, phones, emails, device or IP signals, and fragments of payment data—are also useful to criminals for phishing, account takeover, and social engineering. Public background on the sector does not prove negligence in this case; it simply explains why the alleged exposure of tens of millions of rows matters to ordinary people who only ever shopped at a third-party store.

The information in question

The facts name the following exposed data types: email addresses, IP addresses, names, partial credit card data, passwords, phone numbers, and physical addresses. Reporting further specifies names and bcrypt password hashes for users, and for other records names, phone numbers, physical addresses, and partial credit card data limited to card type and last four digits. The dataset was described as 147 tables totalling about 65 GB, with 16 million unique email addresses among tens of millions of rows.

Where public detail stops, it should not be filled in by assumption. Full primary account numbers, CVVs, or plain-text passwords are not stated as exposed in the given facts. Exact confirmation of every field for every individual, the proportion of direct users versus merchant customers, and whether all listed rows are accurate remain subject to the limits of the reported summary. Organisations in this sector commonly hold order metadata, contact details, and risk scores; that general practice helps explain why such fields appear, but it does not expand the confirmed contents of this incident beyond what has been named.

The real-world impact

For affected individuals, the practical risks are concrete. Email addresses combined with names and phone numbers enable targeted phishing and smishing that reference real orders or fake “fraud alerts.” Physical addresses can support package-related scams or more persuasive social engineering. IP addresses may add context for tracking or for crafting messages that look local or device-specific. Bcrypt password hashes do not immediately equal account takeover, but if the underlying password was weak or reused on other sites, offline cracking can still succeed and lead to credential stuffing elsewhere. Partial credit card data—card type and last four digits—is not enough by itself to place new charges, yet it can increase the credibility of payment-related fraud attempts or help criminals match records from other leaks.

For the organisation and the merchants that relied on it, the impact includes loss of trust, potential regulatory and contractual scrutiny, and the operational cost of investigation and customer notification. People who never created an Eye4Fraud account may still be in the data if a shop they used sent order details for fraud screening. That indirect exposure is a recurring feature of breaches in payment and fraud infrastructure and is one reason the reported 16 million unique emails represent a wide circle of potential harm rather than a narrow user list alone.

What to do if you're exposed

If you believe you may be in this dataset—whether as a direct user or as a customer of a merchant that used Eye4Fraud—treat the risk as real but manageable. Change passwords on any account where you may have reused a credential associated with shopping or fraud-protection flows, and enable multi-factor authentication wherever it is offered. Treat unsolicited messages that cite orders, addresses, or partial card digits with caution; verify through official app or website channels rather than links in email or text. Monitor bank and card statements for unusual activity and consider fraud alerts with your card issuers if you are concerned about related scams. Review account recovery settings on major email and shopping accounts so that phone numbers and secondary emails cannot be easily abused.

You can also run a free exposure scan of your email to check whether your information has surfaced in known breach data. That check does not undo a leak, but it helps you prioritise which accounts to secure first and whether your address appears in other circulating sets beyond this incident.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyEye4Fraud security record
73/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See Eye4Fraud’s full breach history →

More recent breaches

Hathway Data Breach (2023)December 17, 2023InflateVids Data Breach (2023)December 12, 2023KitchenPal Data Breach (2023)November 14, 2023Facebook Marketplace Data Breach (2023)October 1, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Eye4Fraud Data Breach (2023) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram