Market Moveis Data Breach (2023)
If you are a customer of Market Moveis, here’s what’s now in circulation.
In August 2023, the Portuguese home decor company Market Moveis suffered a data breach that impacted 28k records. The exposed records were limited to names and email addresses.
On August 30, 2023, the Portuguese home decor retailer Market Moveis appeared in a breach notification that confirmed 28,000 records containing customer names and email addresses had been exposed.
Watch Market Moveis
Get alerted the next time Market Moveis files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Market Moveis’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (up to 500 companies) is GalaxyWarden Signals — $299/mo or $2,990/yr (indicative estimate).
Reported Details from the Disclosure
The listing on Have I Been Pwned states that the incident occurred in August 2023 and that the compromised data set was limited to names and email addresses. The notification does not specify the attack vector, whether the data was encrypted, or if any ransom was demanded. It also does not indicate whether passwords, payment details, or physical addresses were included. The breach was added to the database after the company or a researcher submitted the sample dataset for verification.
Why This Matters for You and Your Family
When a company that sells furniture and home goods holds your name and email, the exposure may feel minor, yet it creates a permanent record that can be combined with other leaks. Names paired with emails remain one of the most common building blocks used in phishing campaigns, account takeover attempts, and identity-verification attacks. If you or anyone in your household has shopped at Market Moveis, that pairing now sits in multiple underground databases and can surface years later.
The Doxxing and Identity-Chain Risk
Email addresses rarely exist in isolation. Once an attacker obtains your name and email from Market Moveis, they can cross-reference it against credential-stuffing lists, social-media scrapes, and previous breaches. This process quickly links your shopping account to gaming usernames, family photos, children’s school emails, or even smart-home device logins. The result is an identity chain that turns a low-severity retail breach into a gateway for harassment, SIM-swapping, or targeted social engineering against you or your children. Credential leaks like this one frequently cascade into gaming account takeovers because the same email is often reused for Steam, Roblox, or Fortnite.
What to Do
- Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity, then use the cleanup of Warden to remove what you can.
- Rotate the password used at Market Moveis anywhere it is reused and enable 2FA through an authenticator app rather than SMS.
- Enable continuous DoxxScan monitoring across 13.1 billion+ breach records and 100-plus platforms so the next exposure is caught in hours instead of months.
- Cover the household with DoxxScan family protection that extends to dependents and children’s gaming accounts that often chain back to the same email or address.
- Let remediation specialists handle ongoing takedown requests across data brokers and leak sites on your behalf.
The incident underscores that even a seemingly small breach of names and emails can feed larger doxxing chains if left unchecked. Start your DoxxScan trial today and place continuous monitoring, identity-chain mapping, and hands-on remediation between your family and the expanding pool of stolen personal data. GalaxyWarden’s DoxxScan service delivers exactly that combination of broad monitoring, AI-powered linkage detection, and specialist support for households.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…