On June 11, 2024, Italian online marketplace MercatinoUsato.com appeared on the RansomHub leak site with 1.5 TB of claimed internal files exfiltrated during a ransomware attack. The listing remains unpublished, meaning the data has not yet been openly released, but the extortion group has placed the company on public display to pressure payment. Anyone who has bought or sold on the platform, or whose personal details sit in its databases, now faces the possibility that sensitive records are in criminal hands.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Mercatino
Get alerted the next time Mercatino files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Mercatino’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The RansomHub leak page states that Mercatino was compromised in a ransomware operation and that attackers successfully exfiltrated 1.5 TB of internal files. The disclosure does not specify the exact data types taken, the number of affected individuals, or the systems accessed. It simply lists the company, the claimed volume, and a visit counter that stood at 87 when first indexed. The sample files or full archive have not been published as of the latest available information from the onion site. Public reporting on RansomHub indicates the group typically uses this initial listing phase to signal seriousness before escalating to data dumps if demands go unmet.
Why This Matters for You and Your Family
When a marketplace like Mercatino suffers a breach, the exposure often includes names, addresses, phone numbers, email accounts, payment details, and transaction histories of everyday users. Even though the precise records remain unknown, 1.5 TB of internal files is large enough to contain information on hundreds of thousands of Italian households. If your email or phone number was used to register an account, sell a used car, or buy second-hand goods, those details could now sit in an attacker’s archive. For families this creates overlapping risks: one parent’s data can expose children’s names and school-related messages, while shared addresses link every member to the same incident.
Doxxing and Identity-Chain Risks
Stolen marketplace data rarely stays isolated. Attackers and subsequent buyers routinely combine it with other leaks to build full identity profiles. An email from Mercatino can be cross-referenced with credential dumps, social-media handles, and gaming accounts, quickly turning a simple transaction record into a doxxing chain. Public reporting on similar incidents shows that once personal details surface on dark-web forums, they fuel SIM-swapping attempts, account takeovers, and targeted harassment. Credential leaks like this one cascade into account takeovers that can reach your children’s gaming profiles, where the same password or security questions may have been reused.