Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
underground-data-leakmass-credential-exposurethird-party-vendor-breachransomware-group-operation

Dark Web Leak Claims Target Multiple Organizations, Including Salesfloor and Republic

Updated 3mo agoFirst seen Jan 27, 20269 sources

Dark web monitoring reports surfaced multiple alleged data leaks affecting unrelated organizations, with several listings offering databases for sale or direct download. Reports claim Republic (republic.com) user data (~4.94M users) was listed for sale for $2,400, allegedly including names, emails, physical addresses, and phone numbers. Separate dark web listings also alleged exposure of rueducommerce.fr user data (linked in reporting to Carrefour) totaling ~2.17M records with similar PII, as well as alleged leaks involving Dunzo (~3.4M records) and Menulux (~93K records). Additional reporting highlighted a historical breach dataset for the YouHack forum (2013; ~107K users) containing usernames, emails, passwords, IPs, posts, and private messages, and a smaller exposure tied to buylottoonline.com (~38.5K email records).

One of the most consequential claims involved Salesfloor / People Powered E-Commerce (salesfloor.net), attributed in reporting to LAPSUS$, alleging theft of roughly 4 TB uncompressed (1 TB compressed) data including source code, logs, and customer information, with potential downstream impact to retail brands using the platform. Separately from the dark-web-leak theme, other items in the set describe distinct vulnerability-driven risks rather than breach listings: Zoom Node MMRs command injection (CVE-2026-22844, CVSS 9.9) enabling arbitrary code execution in certain hybrid meeting deployments; SmarterMail auth bypass (CVE-2026-23760) enabling admin password reset via force-reset-password and potential RCE; Vite improper access control (CVE-2025-31125) enabling sensitive file exposure via query parameters such as ?inline&import / ?raw&import (noted as added to CISA KEV); and Appsmith password-reset token exposure (CVE-2026-22794) enabling account takeover, with internet-exposed instances identified via Shodan and remediation via upgrade to Appsmith 1.93. These vulnerability reports are separate from the dark web leak claims and should be tracked as independent patching priorities rather than as part of a single breach event.

Share:
Dark Web Leak Claims Target Multiple Organizations, Including Salesfloor and Republic
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

14 events from the most recent confirmed update back to the earliest known activity.

14 EVENTS
Jan 27, 20265mo ago

Dark web seller advertised auction of 1,000 credit cards

SOCRadar reported on 2026-01-27 that a threat actor was auctioning 1,000 credit cards from multiple regions, claiming a 60% validity rate. The listing stated the auction would end on 2026-02-28.

Axtria source code and internal repositories were allegedly leaked

A dark web post reported by SOCRadar on 2026-01-27 claimed Axtria had suffered a breach exposing proprietary source code and internal development repositories. The allegedly leaked material included analytics-related components and infrastructure or deployment configurations.

SOCRadar reported new dark web posts for Axtria, Salesfloor, and Republic

On 2026-01-27, SOCRadar said its Dark Web Team observed new underground posts alleging an Axtria source code leak, a LAPSUS$-attributed Salesfloor breach, and a Republic user database sale. The report largely reinforced and expanded on existing claims around Salesfloor and Republic while introducing Axtria as a newly alleged victim.

Jan 26, 20265mo ago

Menulux customer data leak was disclosed

On 2026-01-26, dark web monitoring identified a reported Menulux data leak affecting about 93,000 customer records. The exposed information was described as including full names, phone numbers, and physical addresses.

Jan 25, 20265mo ago

FAU data leak was publicly disclosed

FAU Erlangen-Nürnberg was publicly reported on 2026-01-25 as having suffered a data leak tied to the earlier claimed September 2025 breach. The disclosure said student data and internal source code had been exposed.

Dunzo leak claims surfaced on dark web

On 2026-01-25, reports emerged alleging exposure of a Dunzo database containing approximately 3.4 million records. The data was described as including user email addresses, phone numbers, and full names, though authenticity was still being verified.

Jan 22, 20265mo ago

Salesfloor breach claims surfaced and were attributed to LAPSUS$

A security incident involving Salesfloor was publicly reported on 2026-01-22, with claims that LAPSUS$ accessed internal systems and exposed a large dataset. The alleged leak included source code, system logs, customer information, and roughly 4TB of uncompressed data affecting about 1 million records.

Carrefour-linked RueDuCommerce database leak surfaced

On 2026-01-22, reports surfaced alleging exposure and sale of a rueducommerce.fr database tied to Carrefour. The listing claimed 2,167,681 user records containing names, email addresses, phone numbers, and physical addresses.

Jan 21, 20265mo ago

Republic user database was reportedly offered for sale

Republic was publicly linked on 2026-01-21 to an alleged dark web sale of a user database containing about 4,942,704 records. The exposed data was described as including names, email addresses, physical addresses, and phone numbers.

BuyLottoOnline breach was publicly reported

On 2026-01-21, a data breach involving buylottoonline.com was publicly reported, describing exposure of roughly 38,521 records. The report did not identify a threat actor or root cause.

YouHack historical breach was publicly reported

A security incident report published on 2026-01-21 disclosed the 2013 YouHack breach and the categories of exposed user data. The incident was treated as informational severity in current reporting.

Oct 29, 20258mo ago

BuyLottoOnline data reportedly exposed in late October 2025

Reports state BuyLottoOnline suffered a breach around 2025-10-29 that exposed about 38,521 records, primarily unique email addresses. No threat actor or root cause was publicly identified.

Sep 25, 20259mo ago

FAU breach reportedly exposed student data and source code

Reports claim Friedrich-Alexander-Universität Erlangen-Nürnberg was breached on 2025-09-25, leading to exposure of student data and internal source code. Specific data types and the technical cause were not confirmed.

May 29, 201313y ago

YouHack breach exposed 107,358 forum user records

A historical breach of the YouHack forum reportedly occurred on 2013-05-29, exposing 107,358 records including usernames, email addresses, passwords, IP addresses, forum posts, and private messages. No threat actor was identified in the later reporting.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
Threat actors
1 linked
Organizations
10 linked
RepublicSOCRadarSalesfloorAxtriaUpGuardCarrefourYouHackRue du CommercePeople Powered E-CommerceDunzo
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Dark Web Leak Claims Target Multiple Organizations, Including Salesfloor and Republic | Mallory