The Power Buy Co. Ltd Leak: 115,000 Customer Records Exposed. Yours Might Be One.
HEROIC analysts found a dataset tied to Power Buy Co. Ltd posted on a hacking forum in May 2023. The company, a major Thai electronics and home appliance e-commerce retailer, had over 115,000 customer records exposed in a direct database compromise. The data was organized, structured, and immediately usable by anyone who downloaded it, with no additional processing needed to identify and target individual customers.
Thai Electronics Shoppers' Contact Details Are Now in Attacker Hands
With names, email addresses, and phone numbers all in a single file, attackers can launch targeted phishing campaigns and smishing attacks with very little effort. They can send messages that reference your real name, appear to come from Power Buy, and direct you to fake login pages designed to harvest your credentials. Because this is an electronics retailer, scams related to order confirmations, warranty claims, and product returns are partcularly convincing angles for attackers to exploit.
What Was Exposed in the Power Buy Co. Ltd Breach
- Email addresses
- Phone numbers
- First and last names
Why E-Commerce Customer Data Fuels Ongoing Fraud
When an e-commerce platform loses customer data, the damage does not stop at a single phishing attempt. The data gets traded across multiple underground forums, recieved by new threat actors who run fresh campaigns months or even years after the original breach. Credential stuffing attacks use your email to probe other accounts. Social engineering calls use your name and purchase history context to build false trust. Identity theft becomes easier when attackers can verify your identity using real data points you never knowingly shared with them.
How a Database Breach Works
E-commerce platforms like Power Buy store customer records in structured databases that back their ordering and account systems. Attackers target these databases through web application vulnerabilities, unprotected API endpoints, or compromised staff credentials. Once access is gained, the attacker queries the database and exports the customer table as a flat file. That file then travels from private channels to public forums, where it becomes permanently accessable to anyone looking for it.
Check If Your Data Was Exposed
HEROIC's free breach scanner covers more than 400 billion records from breaches around the world. If you have ever shopped at Power Buy or used an email address on any Thai e-commerce platform, run a free scan at HEROIC.com to see exactly what data of yours has been exposed and get clear guidance on what to do next.
Breach Breakdown
115,821 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds