Skip to content
Back to Blog
high severity January 25, 2023 · 3 min read

Eye4Fraud Data Breach (2023)

If you are a customer of Eye4Fraud, here’s what’s now in circulation.

In February 2023, data alleged to have been taken from the fraud protection service Eye4Fraud was listed for sale on a popular hacking forum. Spanning tens of millions of rows with 16M unique email addresses, the data was spread across 147 tables totalling 65GB and included both direct users of the service and what appears to be individuals who'd placed orders on other services that implemented Eye4Fraud to protect their sales. The data included names and bcrypt password hashes for users, and names, phone numbers, physical addresses and partial credit card data (card type and last 4 digits) fo

Eye4Fraud Data Breach (2023)

On January 25, 2023, Eye4Fraud appeared in a major breach notification after data allegedly stolen from the fraud-protection service was listed for sale on a popular hacking forum. The dataset contained information on 16 million unique email addresses and affected both direct customers of Eye4Fraud and individuals who had placed orders on merchant sites that used the company’s anti-fraud tools. If your email is among those 16 million, your name, physical address, phone number, partial credit card details, IP address, and password hash may now be in criminal hands.

Named in this incident?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

Reported Details from the Disclosure

The primary listing, as documented by Have I Been Pwned, states that the breach occurred in February 2023 and involved 147 database tables totaling roughly 65 GB. Exposed records include email addresses, names, physical addresses, phone numbers, IP addresses, bcrypt password hashes, and partial credit card data showing only the card type and last four digits. The disclosure indicates the data set contains both Eye4Fraud’s own user accounts and downstream customer records from merchants who integrated the service. Exact ransom demands and the identity of the initial intruder were not published in the primary notification.

Exposure Pack · one payment
The full list, and what to lock in ten minutes.
  • Every indexed leak tied to your address — all of them, named and dated
  • A deeper search of collected breach data — the kinds of your information it holds, where it finds you
  • What this kind of incident typically exposes
  • A ten-minute lock list written for this kind of organisation
One payment. Nothing renews, and no account is created. Emailed to you within a minute.

Why This Matters for You and Your Family

When a fraud-protection company is breached, the consequences reach far beyond that single service. The same names, addresses, and phone numbers you provided to make a legitimate purchase are now available to identity thieves who can combine them with the partial card data to attempt account takeovers or new-account fraud. Passwords protected only by bcrypt can still be cracked offline given enough time and computing power, especially if you reused the same password on other sites. For families this means a single breach can expose both parents and children if shared emails or household addresses were used during checkout.

The exposure of IP addresses further allows attackers to correlate your online activity across services, making targeted phishing or SIM-swapping attempts more convincing and more dangerous.

Doxxing and Identity-Chain Risks

Once names, addresses, phones, and emails are public, criminals begin building identity chains that link your gaming usernames, social-media handles, and family relationships. A child’s gaming account tied to a parent’s breached email can quickly become the entry point for doxxing, harassment, or further credential theft. These chains grow silently until someone sells a full dossier on a dark-web marketplace. The partial credit-card data adds immediate financial risk because many merchants still accept “card type + last four + address” as verification for resets or new orders.

What to Do

  • Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity, then use the cleanup of Warden to break those chains.
  • Rotate the password used at any site that shared data with Eye4Fraud anywhere it is reused, replace it with a unique passphrase, and enable 2FA through an authenticator app rather than SMS.
  • Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next time your information surfaces you learn within hours instead of months.
  • Cover the household with DoxxScan family coverage that extends to dependents and children’s gaming accounts which often chain back to the same breached address or parent email.
  • Let remediation specialists handle ongoing takedown requests across data brokers and leak sites on your behalf while you focus on securing day-to-day accounts.

The Eye4Fraud incident shows how quickly a single service breach can ripple into long-term identity exposure for ordinary families. Acting promptly on the credentials and contact details already circulating can limit further damage. DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1 billion+ breach records and more than 100 platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage that includes children’s gaming accounts at risk of cascading takeovers.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample580 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on Eye4Fraud.

  1. Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Were you a Eye4Fraud customer?
Eye4Fraud is one listing. Your email is probably in others.
16.0M accounts were exposed here. Check whether yours is one — and find every other leak tied to the same address, in about 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High includes account details that can be misused directly
Disclosed January 25, 2023
Last reviewed July 22, 2026
Affected 16.0M
Data exposed Email addressesIP addressesNamesPartial credit card dataPasswordsPhone numbersPhysical addresses
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email