Data breach
ShopBack
- Records
- 21,039,934
- Breach date
- 17 September 2020Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 4 more reported
- Email addresses21,039,922
- Names234,378
- Bank account numbersReported, not counted
- GenderReported, not counted
- Dates of birthReported, not counted
- Phone numbersReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
ShopBack, a Singapore-based e-commerce cashback platform, suffered a data breach in September 2020 after a hacker used a stolen access key to pull customer data from the company's storage servers. The company disclosed the incident on September 17, 2020, and the stolen database later surfaced for sale on a criminal forum. According to our investigation team, the indexed copy of this breach contains more than 21 million records, nearly all of them email addresses, along with about 234,000 names. Singapore's data protection regulator later confirmed the breach affected more than 1.4 million customers and fined the company.
September 9, 2020: According to Singapore's Personal Data Protection Commission (PDPC), a hacker used an AWS access key that had been exposed in the commit history of a private GitHub repository to steal data from ShopBack's customer storage servers.
September 17, 2020: ShopBack discovered the unauthorized access during a routine security review, removed the access, and engaged external cybersecurity specialists. The company notified customers by email and informed the PDPC.
November 12, 2020: The stolen customer data was offered for sale on RaidForums, an online forum used for trading stolen databases, according to the PDPC decision.
November 2024: The PDPC fined ShopBack S$74,400 over the breach, citing a lack of robust processes for managing access keys.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (21,039,922 records) and names (234,378 records).
ShopBack's customer notice, published on its Malaysian support site, said the types of data customers may have provided could include contact information, gender, date of birth, identification numbers for customers in a Plus! loyalty programme campaign that ran from November 2014 to January 2016, and bank account numbers for customers who cashed out to their bank accounts. The notice stated that account passwords were hashed with a unique and dynamic salt.
The PDPC's findings, reported by The Straits Times, put numbers on the wider customer database: email addresses of about 1.4 million users, 840,000 names, 450,000 mobile numbers, 300,000 bank account numbers, and partial credit card information for about 380,000 users. The company said it does not store full 16-digit card numbers or CVV codes.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The most immediate risk is phishing. ShopBack itself warned customers who had provided bank account numbers to watch for phishing attempts, since criminals can use real names, email addresses, and partial financial details to craft convincing scam messages.
Stolen email addresses and passwords, even hashed ones, are routinely used in credential stuffing attacks. If you reused your ShopBack password on other sites, those accounts could be at risk. Identification numbers and bank account details can also support identity fraud, such as impersonation in banking or government-related scams.
What Is ShopBack Doing in Response?
After discovering the breach, ShopBack removed the unauthorized access, reversed changes made by the intruder, forced a logout and password reset across all customer accounts, and engaged external cybersecurity specialists. It notified customers and Singapore's Personal Data Protection Commission. In November 2024, the PDPC fined the company S$74,400, finding that the exposed access key had gone unaddressed for roughly 15 months and that key rotation took 15 days after discovery. The regulator also noted mitigating factors, including ShopBack's prompt remedial actions and cooperation with the investigation.
What Should You Do If You Were Affected?
Change your ShopBack password, and change it anywhere else you used the same one.
Watch for phishing emails or messages that reference ShopBack, your bank, or your cashback balance. Do not click links or respond to suspicious messages.
If you cashed out to a bank account, monitor your statements for unfamiliar activity and be cautious of anyone claiming to be from your bank.
Enable any additional security features ShopBack offers, such as linking a mobile number to your account.
In the news
- The Straits Times: ShopBack fined $74,400 over data leak that affected more than 1.4 million usersstraitstimes.com (opens in a new tab)
- The Jakarta Post: ShopBack and RedDoorz report data breachesthejakartapost.com (opens in a new tab)
- ShopBack Customer Notice FAQs (Malaysia support site)support.shopback.my (opens in a new tab)
- RPC: Fines for PDPA Breachesrpclegal.com (opens in a new tab)
- The Business Times: ShopBack fined S$74,400 for breach of data of over a million users
