The AidanGrayLiving Breach Means Scammers Have Your Name and Phone Number
HEROIC analysts recieved a dark web alert in November 2022 tied to AidanGrayLiving, a US-based e-commerce retailer specializing in home furnishings and decor. The exposed dataset contained 6,657 records drawn directly from the platform's customer database, covering email addresses, phone numbers, first names, and last names. No passwords were included, but the personal contact profile assembled from these four fields is more than enough to enable targeted fraud and harassment campaigns against affected customers.
How Attackers Use Customer Profiles for Phishing and Fraud
A dataset combining full names, email addresses, and phone numbers is a ready-made targeting list for social engineering. Attackers can craft personalized phishing emails addressed to the victim by name, referencing their relationship with AidanGrayLiving to build false credibility. The same data fuels SMS fraud campaigns where victims receive convincing text messages about fake orders, shipping delays, or account problems. This type of contact data is partcularly valued by fraud operations because it sidesteps the need to crack passwords entirely: the goal is to trick the victim into providing credentials or financial details directly.
What Was Exposed in the AidanGrayLiving Breach
- Email Address
- Phone Number
- First Name
- Last Name
The AidanGrayLiving Breach Means Someone Has Your Name and Phone Number
For the 6,657 customers whose data occured in this breach, the practical risk is targeted contact from criminals who know exactly who you are and where to reach you. Scammers using this data can impersonate customer service representatives, delivery companies, or financial institutions with a level of personalization that makes the deception convincing. Victims of these attacks often end up disclosing payment information, clicking malicious links, or installing malware on their devices. The seperate concern for US-based victims is that their information may also be cross-referenced with other data broker sources to build more complete profiles for identity theft.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a web application's backend database and extracts customer records. Common attack vectors include SQL injection, compromised admin credentials, or insecure API endpoints that expose database contents without authentication. Once an attacker copies the database tables, the data is packaged and distributed through dark web forums where it is purchased by fraud operators for use in phishing, smishing, and identity theft campaigns.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records, including the AidanGrayLiving breach and thousands of other known leaks. Enter your email at HEROIC.com to see a complete exposure report and find out exactly which of your personal details are in circulation on the dark web.
Breach Breakdown
6,657 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds