LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Genesis Market Data Breach (2023)

CRITICAL severityConfirmedHow we verify

Genesis Market Data Breach (2023): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·April 5, 2023

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Genesis Market Data Breach (2023)

Reported April 5, 2023. Approximately 8.0M people affected.

CRITICAL
Severity
8.0M
People affected
10
Data types exposed
April 5, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Genesis Market Data Breach (2023) (reported April 5, 2023) exposed Browser user agent details, Credit card CVV, Credit cards and Dates of birth belonging to roughly 8.0M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Exposes financial/biometric data.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Genesis Market Data Breach (2023) breach?
8.0M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In April 2023, law-enforcement action against Genesis Market brought into public view a large volume of personal and financial data that the service had been trading. Roughly eight million people may be connected to records held there. For anyone whose browser details, credentials, or payment data were among them, the practical risk is that criminals could already have used that material to impersonate them online or attempt fraud.

Public reporting ties the incident to the shutdown of the marketplace itself rather than to a conventional corporate hack of an ordinary company. Exact counts and the full contents of every record remain approximations, but the types of data named make clear why ordinary users should treat the event seriously.

What happened

On or around 5 April 2023, Genesis Market was shut down by the FBI and a coalition of law-enforcement agencies in an operation publicly referred to as “Operation Cookie Monster.” The service had operated as a stolen-identity marketplace that sold “browser fingerprints” and related account data, enabling buyers to impersonate victims and reach their online services.

Reporting associated with the shutdown indicates that approximately 8 million people were affected. That figure is described as an approximation of scale, in part because many of the impacted accounts did not include email addresses. Named categories of exposed information include browser user-agent details, credit-card numbers and CVV values, dates of birth, email addresses, names, passwords, and phone numbers. Additional personal data such as addresses and credit-card information were also compromised by the service, though not every individual record contained every field.

No further public detail is given in the available record about the precise technical method by which the marketplace originally obtained the data, the exact file inventories seized, or a definitive head-count beyond the stated approximation.

How a breach like this happens

Incidents involving stolen-identity marketplaces typically begin with large-scale collection of credentials, session cookies, browser configuration data, and payment details. Collection methods commonly include malware on victim devices, phishing, or purchase of already-stolen logs from other criminals. Once gathered, the material is packaged—often as “bots” or fingerprint profiles that recreate a victim’s browser environment—and offered for sale so buyers can bypass simple login checks and appear to be the legitimate user.

When law enforcement dismantles such a marketplace, the underlying trove of stolen data becomes visible to investigators and, in many cases, is later reflected in breach-notification and exposure-checking services. The shutdown itself does not erase copies that buyers may already have downloaded. Because no specific threat group is attributed in the facts of this case beyond the law-enforcement action, the general pattern above is offered only as background on how services of this type ordinarily function.

Who is Genesis Market?

Genesis Market was an underground marketplace that specialised in the sale of stolen digital identities, with a particular emphasis on browser fingerprints and associated account data. In the cybercrime economy, such platforms sit between initial data thieves and fraudsters who need ready-to-use profiles for account takeover, fraudulent purchases, or further social engineering.

Organisations of this kind typically hold large volumes of highly sensitive personal and financial information precisely because that is the merchandise. A law-enforcement takedown is therefore consequential: it both removes a major distribution channel and surfaces the scale of data that had been circulating. The fact that Genesis Market dealt in material enabling direct impersonation of ordinary internet users is what makes the exposure relevant far beyond the criminal underground.

What was likely exposed

The available facts name the following data types as exposed: browser user-agent details, credit-card CVV values, credit-card numbers, dates of birth, email addresses, names, passwords, and phone numbers. Reporting also notes that names, addresses, and credit-card information were among the personal data compromised by the service, while emphasising that not every individual had each of these fields present.

Because many records lacked email addresses, the widely cited figure of roughly 8 million affected people is an approximation intended to convey scale rather than a precise census. Exact contents of any single person’s record remain unconfirmed without further individual notification or verification.

Why it matters

Browser fingerprints and saved credentials allow an attacker to present themselves as the victim to banks, email providers, shopping sites, and other services that rely on device or session recognition. Credit-card numbers and CVV values can be used for fraudulent charges. Names, dates of birth, phone numbers, and addresses support identity fraud and targeted social engineering. Passwords, if reused elsewhere, open additional accounts.

For the people whose data appeared in the marketplace, the harm is concrete: unauthorised access attempts, financial loss, and the administrative burden of securing accounts and monitoring credit. For the broader ecosystem, the shutdown removed one large bazaar but left in circulation whatever copies buyers had already obtained. The absence of a full, field-by-field inventory for every victim means many people must assume exposure until they can check otherwise.

If your data was in this breach

If you believe you may be among those affected, practical first steps include:

Public detail on individual notifications from this incident is limited; checking exposure databases and hardening accounts remain the most direct actions available to ordinary users.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyGenesis Market security record
73/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See Genesis Market’s full breach history →

More recent breaches

Hathway Data Breach (2023)December 17, 2023InflateVids Data Breach (2023)December 12, 2023KitchenPal Data Breach (2023)November 14, 2023Facebook Marketplace Data Breach (2023)October 1, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Genesis Market Data Breach (2023) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram