B
B

BlueSnapRegpack

Breaches
1
1 verified
Records Exposed
105K
Total across all breaches
Data Types Leaked
9
0 high risk
Latest Breach
2016
BlueSnapRegpack

Breach History

BlueSnapRegpack
May 2016High
105K
Records exposed
9
Data types leaked
Verified
Status

In July 2016, a tweet was posted with a link to an alleged data breach of BlueSnap, a global payment gateway and merchant account provider. The data contained 324k payment records across 105k unique email addresses and included personal attributes such as name, home address and phone number. The data was verified with multiple Have I Been Pwned subscribers who confirmed it also contained valid transactions, partial credit card numbers, expiry dates and CVVs. A downstream consumer of BlueSnap services known as Regpack was subsequently identified as the source of the data after they identified human error had left the transactions exposed on a publicly facing server. A full investigation of the data and statement by Regpack is detailed in the post titled Someone just lost 324k payment records, complete with CVVs.

Exposed Data Types
Browser user agent detailsCredit card CVVEmail addressesIP addressesNamesPartial credit card dataPhone numbersPhysical addressesPurchases
Incident Status
Data breachYes
Data brokerNo
Policy contradictionsNo
Exposed Data Types
Browser user agent detailsLow risk
Credit card CVVLow risk
Email addressesLow risk
IP addressesMedium risk
NamesLow risk
Partial credit card dataLow risk
Phone numbersMedium risk
Physical addressesMedium risk
PurchasesLow risk