Pandabuy Data Breach (2024): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Pandabuy Data Breach (2024) (reported March 31, 2024) exposed Email addresses, IP addresses, Names and Phone numbers belonging to roughly 1.3M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In today's threat landscape, online marketplaces and shopping agents that handle cross-border purchases remain frequent targets for data exposure, as their systems routinely process large volumes of customer contact and order details. The Pandabuy incident reported in March 2024 fits this pattern: roughly 1.3 million unique email addresses tied to the service were posted to a popular hacking forum, along with additional personal and order-related information. For people who used the platform to buy goods from China, the event raises practical questions about what was exposed and what steps to take next.
Public reporting places the disclosure on 31 March 2024. The material is described as containing email addresses, IP addresses, names, phone numbers, physical addresses and order enquiries. Attribution has been alleged to the handles "Sanggiero" and "IntelBroker," though those claims remain unconfirmed by independent verification in the available record.
Inside the incident
According to the reported summary, in March 2024 a dataset of 1.3 million unique email addresses associated with Pandabuy was posted to a popular hacking forum. The same material is said to have included IP addresses, physical addresses, names, phone numbers and order enquiries. The incident was reported on 31 March 2024. Public detail on the precise method of access, the duration of any intrusion, or the full technical scope remains limited. The posting itself is the primary public marker of the event; no further official confirmation of internal investigation findings has been included in the available facts.
The breach has been alleged to be attributed to the handles "Sanggiero" and "IntelBroker." That attribution is presented here solely as a claim made in connection with the forum posting and has not been independently verified in the source material.
How a breach like this happens
Incidents of this type typically begin with unauthorised access to a customer database or related systems that store account and order information. Common pathways include compromised credentials, unpatched software vulnerabilities, or misconfigured cloud storage that allows external retrieval of records. Once obtained, the data is often packaged and offered or simply dumped on underground forums for sale, trade or notoriety. In many cases the operators of the affected service learn of the exposure only after the material appears publicly. No specific intrusion technique has been disclosed for the Pandabuy event, so the general pattern above is offered only as background on how similar exposures commonly unfold.
About Pandabuy
Pandabuy operates as an online shopping agent that helps customers purchase goods from China and arrange shipping. Services of this kind typically collect account details, shipping addresses, contact numbers and order histories so they can place purchases on behalf of users and manage logistics. Because the platform sits between international buyers and Chinese sellers, it necessarily holds a concentration of personal identifiers and transaction-related data. A breach at such a service is consequential precisely because that information is both personal and commercially useful to fraudsters who specialise in identity misuse or targeted phishing.
The information in question
The facts name the following data types as exposed: email addresses, IP addresses, names, phone numbers and physical addresses. The reported summary also states that order enquiries were included. Exact file formats, whether passwords or payment-card numbers were present, and the completeness of any individual record are not disclosed. Organisations in this sector commonly retain shipping addresses, phone numbers and order notes in the ordinary course of business; however, the precise contents of the posted Pandabuy material beyond the categories listed above remain unconfirmed.
What's at stake
For affected individuals the concrete risks include phishing emails that reference real order details, attempts to reset accounts using known email addresses, or social-engineering calls that exploit the combination of name, phone number and physical address. Physical addresses can also be used for more targeted fraud or unwanted contact. For the organisation, the exposure of customer records can erode trust, generate regulatory scrutiny in jurisdictions that protect personal data, and create ongoing costs associated with notification and remediation. None of these outcomes is inevitable, but each is a realistic consequence when contact and address data leave authorised control.
Were you affected?
If you have used Pandabuy, treat the possibility of exposure seriously. Change any password that may have been reused on the platform, enable multi-factor authentication wherever available, and monitor email and financial accounts for unusual activity. Be sceptical of unsolicited messages that reference past orders or ask for additional personal details. Readers can also run a free exposure scan of their email address to check whether it has appeared in known breach datasets. Doing so provides a practical first indication of whether further vigilance is warranted.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Speedio Data Breach (2024)Young Living Essential Oils Data Breach (2024)Senior Dating Data Breach (2024)FlipaClip Data Breach (2024)Latest breaches
Read GalaxyWarden’s full analysis of the Pandabuy Data Breach (2024) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.