Data of Nearly 87,000 Customers from Moscow’s Metropolis Mall Leaked Online

Data of Almost 87,000 Metropolis Mall Customers Leaked Online

A database containing information on users of the Metropolis shopping center’s mobile apps (iOS and Android)—one of the largest malls in Moscow—has been found publicly available on a dark web forum. The data dump includes details on 86,883 customers as of February 18, 2022.

How the Leak Happened

According to the Telegram channel “Information Leaks,” a forum member initially tried to sell information about a vulnerability that provided access to Metropolis’s customer database for 300 Monero (over $52,000 at the time). Since there were apparently no buyers, the seller decided to create an SQL dump and release it publicly.

What Information Was Exposed?

The leaked records include the following data:

  • User name
  • Phone number
  • Email address
  • Hashed (bcrypt) password
  • Bonus points balance
  • Account creation and update dates (from July 12, 2018 to February 18, 2022)
  • Links to social media profiles on VKontakte, Facebook, and Instagram

Leave a Reply