Eye4Fraud Data Breach (2023)
If you are a customer of Eye4Fraud, here’s what’s now in circulation.
In February 2023, data alleged to have been taken from the fraud protection service Eye4Fraud was listed for sale on a popular hacking forum. Spanning tens of millions of rows with 16M unique email addresses, the data was spread across 147 tables totalling 65GB and included both direct users of the service and what appears to be individuals who'd placed orders on other services that implemented Eye4Fraud to protect their sales. The data included names and bcrypt password hashes for users, and names, phone numbers, physical addresses and partial credit card data (card type and last 4 digits) fo
On January 25, 2023, Eye4Fraud appeared in a major breach notification after data allegedly stolen from the fraud-protection service was listed for sale on a popular hacking forum. The dataset contained information on 16 million unique email addresses and affected both direct customers of Eye4Fraud and individuals who had placed orders on merchant sites that used the company’s anti-fraud tools. If your email is among those 16 million, your name, physical address, phone number, partial credit card details, IP address, and password hash may now be in criminal hands.
Reported Details from the Disclosure
The primary listing, as documented by Have I Been Pwned, states that the breach occurred in February 2023 and involved 147 database tables totaling roughly 65 GB. Exposed records include email addresses, names, physical addresses, phone numbers, IP addresses, bcrypt password hashes, and partial credit card data showing only the card type and last four digits. The disclosure indicates the data set contains both Eye4Fraud’s own user accounts and downstream customer records from merchants who integrated the service. Exact ransom demands and the identity of the initial intruder were not published in the primary notification.
- Every indexed leak tied to your address — all of them, named and dated
- A deeper search of collected breach data — the kinds of your information it holds, where it finds you
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
Why This Matters for You and Your Family
When a fraud-protection company is breached, the consequences reach far beyond that single service. The same names, addresses, and phone numbers you provided to make a legitimate purchase are now available to identity thieves who can combine them with the partial card data to attempt account takeovers or new-account fraud. Passwords protected only by bcrypt can still be cracked offline given enough time and computing power, especially if you reused the same password on other sites. For families this means a single breach can expose both parents and children if shared emails or household addresses were used during checkout.
The exposure of IP addresses further allows attackers to correlate your online activity across services, making targeted phishing or SIM-swapping attempts more convincing and more dangerous.
Doxxing and Identity-Chain Risks
Once names, addresses, phones, and emails are public, criminals begin building identity chains that link your gaming usernames, social-media handles, and family relationships. A child’s gaming account tied to a parent’s breached email can quickly become the entry point for doxxing, harassment, or further credential theft. These chains grow silently until someone sells a full dossier on a dark-web marketplace. The partial credit-card data adds immediate financial risk because many merchants still accept “card type + last four + address” as verification for resets or new orders.
What to Do
- Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity, then use the cleanup of Warden to break those chains.
- Rotate the password used at any site that shared data with Eye4Fraud anywhere it is reused, replace it with a unique passphrase, and enable 2FA through an authenticator app rather than SMS.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next time your information surfaces you learn within hours instead of months.
- Cover the household with DoxxScan family coverage that extends to dependents and children’s gaming accounts which often chain back to the same breached address or parent email.
- Let remediation specialists handle ongoing takedown requests across data brokers and leak sites on your behalf while you focus on securing day-to-day accounts.
The Eye4Fraud incident shows how quickly a single service breach can ripple into long-term identity exposure for ordinary families. Acting promptly on the credentials and contact details already circulating can limit further damage. DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1 billion+ breach records and more than 100 platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage that includes children’s gaming accounts at risk of cascading takeovers.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Eye4Fraud.
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
149 Million Credential Mega-Exposure — January 2026
Security researchers discovered a publicly exposed 96 GB database with 149 million unique logins cov…
Under Armour 72M Customer Email Dataset Resurfaces — January 2026
72 million user emails from a prior Under Armour breach were reposted publicly in January 2026, ampl…