On August 1, 2022, Malaysian retail company shopper360.com.my appeared on the LockBit 3.0 ransomware leak site. The listing states that internal files were exfiltrated during a ransomware attack, placing anyone whose personal or employment records passed through the company’s systems at risk of exposure.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch shopper360.com.my
Get alerted the next time shopper360.com.my files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about shopper360.com.my’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The LockBit 3.0 leak page claims the group successfully stole internal data from shopper360.com.my and gives the company a deadline to negotiate or face full publication. The listing does not specify the exact number of records taken, the precise data types inside the files, or the initial access vector used. It simply states that internal files were exfiltrated and that samples would be released if the victim refused to pay. As is typical with these sites, the disclosure remains deliberately vague on volume while making clear that sensitive business documents are now in the actors’ possession.
Why This Matters for You and Your Family
When a retail company’s internal files are stolen, the information often includes customer purchase records, employee payroll data, supplier contracts, and contact details that tie real people to real addresses. If your name, email, phone number, or national identification details were ever linked to shopper360.com.my as a customer, employee, or vendor, those records may now sit on a criminal server. The exposure creates immediate risks of identity theft, phishing campaigns tailored to your shopping history, and long-term financial fraud. Even when exact record counts remain unknown, the high severity rating reflects the broad potential for personal harm once such data leaves legitimate control.
Doxxing and Identity-Chain Implications
Stolen internal files rarely stay isolated. Threat actors routinely cross-reference employee or customer spreadsheets against other breaches to build detailed identity chains. A work email from this incident can be paired with a password found elsewhere, a phone number from a past shopping loyalty program, or a home address pulled from public records. The result is doxxing that escalates quickly: harassment on social media, SIM-swapping attempts, or targeted scams against you or your children. Credential leaks of this nature frequently cascade into gaming account takeovers, where a child’s username and reused password become the entry point for further harassment or extortion.