< Back to all clusters
[CRIME] · Indonesia, Vietnam · 2 sources

Hipshipper data breach fuels targeted phone scams in Indonesia and Vietnam

A massive data leak from the global shipping platform Hipshipper, which collaborates with Amazon, eBay and Shopify, exposed 14 million customer records, including names, addresses, identification numbers and bank details. The unprotected AWS storage allowed the information to be accessed publicly for about a month.

Scammers are now using the leaked data to conduct precise phone fraud. Victims receive calls from numbers that read out their personal ID (CCCD) and bank account digits, convincing them to provide additional financial information. The attacks are aided by knowledge of victims' purchase histories and daily habits.

The compromised data is also being sold on underground marketplaces, where criminal groups purchase full personal profiles for a set price. Some fraudsters employ fake mobile transmission devices to broadcast malicious SMS messages containing trojan code to nearby phones.

Entities: Amazon · Hipshipper · Shopify · eBay