If You Used the FarmGo App, Farm Superstores Breach May Affect You
If you have ever shopped through the FarmGo app operated by Farm Superstores, a Saudi Marketing Company supermarket chain, your personal data may have been exposed. HEROIC analysts found that on July 13, 2024, a database breach was identified that compromised 31,250 records from the Farm Superstores customer database. The exposed data includes full names, email addresses, phone numbers, genders, and birthdays, representing a detailed personal profile for each affected individual. This incident affects users located in Saudi Arabia.
Why This Is Dangerous
The combination of full name, email address, phone number, gender, and date of birth creates a rich personal profile that threat actors can use for targeted phishing, social engineering, and identity fraud. Unlike password-only leaks, this type of personally identifiable information (PII) cannot be changed: a person cannot change their birthdate or legal name. The data remains useful to attackers indefinitely.
What Was Exposed
- Email Address
- Phone Number
- First Name
- Last Name
- Gender
- Birthday
Why This Matters
Personally identifiable information of this type fuels identity theft, account takeover (ATO) through targeted phishing, SIM-swapping attacks using the phone number, and fraudulent account creation in victims' names. Attackers who know a person's full name, email, phone number, gender, and date of birth can convincingly impersonate that individual or craft highly personalized phishing messages. Financial fraud and unauthorized credit applications are common downstream consequences. No passwords were exposed in this breach, but the PII alone is sufficient to cause serious harm.
How Database Breaches Work
A database breach occurs when unauthorized parties gain access to an organization's backend data store, typically through vulnerabilities in web applications, misconfigured cloud storage, compromised administrative credentials, or unpatched software. Once inside, attackers extract customer records and either sell them on underground markets or publish them publicly. In the retail and e-commerce sector, customer databases are prime targets because they aggregate detailed personal information from thousands or millions of real individuals in one place.
Check If You Are Affected
HEROIC offers a free dark web scanner that searches across more than 400 billion compromised records to determine whether your email address appears in known breach datasets, including the Farm Superstores incident. If your information was exposed, be alert to unsolicited calls or messages referencing your personal details, avoid clicking links in unexpected emails, and consider placing a fraud alert with relevant credit bureaus. Visit heroic.com to run a free scan now.
Breach Breakdown
31,250 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds