Millions of MyDeal users have data sold online after breach

password manager security
(Image credit: Passwork)

Australian retail marketplace MyDeal has confirmed it suffered a data breach that has affected more than two million of its customers.

The company contacted all affected customers explaining the incident, saying that an unknown attacker compromised its systems and accessed customer identity data. 

According to BleepingComputer, the threat actor managed to obtain the login information for MyDeal’s Customer Relationship Management (CRM) platform, and used it to extract sensitive data belonging to around 2.2 million users.

MyDeal data sold

That data included names, email addresses, phone numbers, postal addresses, and, for some, birth dates. For a smaller subset of users (1.2 million), the hackers only managed to obtain email addresses.

While details on the perpetrators are scarce, what they're doing with the data is clear: trying to sell it on an underground forum for $600. 

According to the company, the number of entries in the database, which is still being parsed by the attacker, currently stands at over one million, with the number predicted to rise. 

To prove the authenticity of the attack, the attackers posted screenshots of MyDeal’s Confluence servers, as well as the Single Sign-On (SSO) prompt for its account with Amazon Web Services (AWS).

MyDeal also said the attackers did not obtain any payment information, identification documents data, or passwords. Still, it suggests users reset their passwords anyway. Such an attack would not have been prevented even with the best password managers.

MyDeal is an Australian retail marketplace that seeks to connect local retailers with potential shoppers.

It was acquired by Woolworths in September 2022, but the supermarket chain claims its systems are on a different platform, and therefore completely safe from the attackers. 

While crooks may not have gotten payment data, or passwords, they still have enough information for identity theft or phishing attacks, so users are urged to remain vigilant.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
A top online gift card store may have exposed private data on hundreds of thousands of users
Representational image of data security
Travel data of almost 500,000 users exposed in Daytrip leak
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Someone checking their credit card details online.
Millions of credit card details leaked online - watch out if you're paying for Christmas
Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 9 (game #1140)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 9 (game #371)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 9 (game #637)
WhatsApp
WhatsApp just made its AI impossible to avoid – but at least you can turn it off