On May 31, 2026, criminal-forum marketing alleged a database dump from MyDukaan (mydukaan.io) containing roughly 100 million user records—names, emails, phones, full shipping addresses, order histories, and encrypted payment API keys. The listing priced the archive at about $10,000 and circulated through security social channels the same weekend. MyDukaan had not published a matching confirmation in indexed English trade press at catalog time, so BreachHistory treats the incident as an unverified actor claim with a high-impact ceiling if samples validate.
Do not confuse MyDukaan with “Dukaan”
Indian e-commerce has two similarly named brands that confuse journalists and victims:
- MyDukaan (mydukaan.io) — the subject of the May 31, 2026 forum listing discussed here.
- Dukaan — a separate merchant platform that Cybernews documented in 2025 after an exposed Apache Kafka stream leaked payment-gateway tokens and customer traffic for years.
Merchants searching “Dukaan breach” may read outdated guidance that does not apply to MyDukaan accounts. Always verify which domain your store actually uses before rotating credentials.
What the forum seller claimed
According to May 31 posts summarized by dark-web monitors, alleged fields included:
- Usernames, first and last names, emails, and phone numbers
- Password or account-status columns (hashing strength unknown)
- Full buyer addresses with city, state, PIN, and country
- Purchase and transaction history, order metadata, and reseller SKU mappings
- Store-lead and seller records tied to merchant operations
- Encrypted payment API keys—high risk if encryption is weak or keys are recoverable
- Activity logs that could reveal business relationships
Criminal sellers often inflate counts by merging recycled tables. Independent researchers should demand verifiable samples before repeating the 100 million figure as fact.
Why this matters for Indian merchants
MyDukaan-style platforms sit between consumers and thousands of small sellers. A validated leak would fuel:
- Credential stuffing against merchant admin panels and buyer accounts
- Invoice and refund phishing referencing real order numbers
- Payment fraud if API keys or tokens can be decrypted or misused
- Supply-chain scams targeting store leads and reseller contacts
Immediate steps for store owners
- Log into MyDukaan only via bookmarked URLs—ignore “security update” links in SMS or WhatsApp.
- Rotate admin passwords and enable MFA on email accounts used for password recovery.
- Regenerate payment-gateway keys (Razorpay, PayPal, Stripe, etc.) if your platform allows—assume keys in the alleged dump are compromised until disproven.
- Notify customers only after official company guidance to avoid copycat phishing.
- Report suspicious transactions to your payment processor immediately.
Immediate steps for shoppers
Buyers who purchased through MyDukaan-powered storefronts should:
- Change passwords on affected stores and anywhere the same password was reused
- Watch bank/UPI alerts for unauthorized charges
- Be skeptical of delivery or refund messages citing exact order details—criminals use leaked orders for convincing scams
Timeline: May 31 weekend claim cycle
The alleged MyDukaan listing appeared in the same 72-hour window as other high-volume forum sales (Iran Hajj records, Pakistan HEC education data, and Colombia POS vendor GamaSoft). That clustering is typical of criminal marketplaces batching “fresh” dumps before Memorial Day–weekend news cycles in Western media. Security teams should treat the timing as a signal to heighten fraud monitoring, not as proof that MyDukaan was actually breached on that exact calendar day—sellers routinely backdate archives.
How researchers should verify (or debunk) the dump
Responsible disclosure starts with evidence, not headline counts:
- Sample hashes: Compare a small set of leaked emails or order IDs against voluntary merchant reports (with consent).
- Password formats: bcrypt/scrypt/argon2 hashes suggest a production DB export; plaintext or MD5 may indicate recycled combo lists.
- Payment keys: If alleged API secrets decrypt or authenticate against live gateways, assume active fraud and force key rotation platform-wide.
- Row uniqueness: De-duplicate on email+phone; forum “100M” often counts join-table explosions.
Until MyDukaan publishes indicators of compromise (IOCs), breach dates, or notification plans, BreachHistory keeps verification status at unconfirmed.
Regulatory and industry context
India’s Digital Personal Data Protection Act (DPDPA) and sector guidelines increasingly expect quick breach notification when personal data is compromised, with emphasis on data fiduciaries protecting principals (buyers and merchants). Cross-border sellers using MyDukaan for export orders may also trigger GDPR or UK GDPR duties if EU/UK buyer data is involved. Until MyDukaan or regulators speak, journalists should label the event as an alleged forum sale, not a confirmed statutory breach with a finalized victim count.
UPI, wallets, and payment processors
Even if buyer card data were not in the alleged dump, Indian checkout flows often combine UPI handles, wallet tokens, and processor API keys in merchant backends. Rotating Razorpay, Cashfree, PayU, or Stripe keys is cheaper than absorbing chargebacks after criminals script unauthorized captures. Enable processor-side velocity rules and webhook signing checks after any SaaS marketplace incident.
How BreachHistory catalogs the claim
Our canonical row mydukaan-forum-megaleak2026 stores the actor-claimed 100,000,000 figure in the headline field with clear verification caveats in the technical write-up. We will lower the count if the company publishes an attested denominator or if researchers disprove the dump’s authenticity.
Related spring 2026 incidents
MyDukaan surfaced in the same news cycle as other global forum megaleaks—see our late May leak-site roundup and breach blog for parallel claims. Enable monitoring if you track Indian SaaS vendors.
Canonical record: MyDukaan 2026 alleged database claim. Explore platform tools and the MyDukaan company timeline.
Enterprise and investor checklist
If you underwrite Indian SMB SaaS, add MyDukaan to third-party risk reviews: demand SOC 2 or ISO 27001 artifacts, subprocessor lists, encryption-at-rest statements, and incident-response SLAs. Portfolio companies white-labeling MyDukaan storefronts should document data-processing agreements before the claim hardens into regulatory action.
Sources: Dark Web Informer (May 31 listing), Cybernews (prior Dukaan incident, for context)