
What was exposed, when it happened, and which databases confirm it.
- accounts
- 153,324
- Breached
- May 20, 2016
- Last Update
- September 13, 2016
Were you caught in this breach?
Search your email, phone number or username against every record CheckLeaked indexes.
What happened
In July 2016, a tweet was posted with a link to an alleged data breach of BlueSnap, a global payment gateway and merchant account provider. The data contained 324k payment records across 105k unique email addresses and included personal attributes such as name, home address and phone number. The data was verified with multiple Have I Been Pwned subscribers who confirmed it also contained valid transactions, partial credit card numbers, expiry dates and CVVs. A downstream consumer of BlueSnap services known as Regpack was subsequently identified as the source of the data after they identified human error had left the transactions exposed on a publicly facing server. A full investigation of the data and statement by Regpack is detailed in the post titled Someone just lost 324k payment records, complete with CVVs.
Compromised Info
- Browser user agent details
- Credit card CVV
- Email addresses
- IP addresses
- Names
- Partial credit card data
- Phone numbers
- Physical addresses
- Purchases
Attestation
Four independent databases catalog this breach and they do not always agree. Each lane below is one source’s own count.
Sources & Link Methods
- HIBP
FAQ
What was leaked in the BlueSnapRegpack breach?
The BlueSnapRegpack breach exposed: Browser user agent details, Credit card CVV, Email addresses, IP addresses, Names, Partial credit card data, Phone numbers, Physical addresses, and Purchases.
When did the BlueSnapRegpack breach happen?
The BlueSnapRegpack breach was disclosed on May 20, 2016 and affected 104,977 records.
Am I affected by the BlueSnapRegpack breach?
Search your email, phone or username at checkleaked.cc to find out whether your data appears in the BlueSnapRegpack leak.