← Blog

Pi Wallet Breach: 3.5M Taiwan Users in Settra Ransomware Hit

Share on X

June 30, 2026: Taiwan's Pi Wallet (Pi錢包)—a major mobile payment service operated by PayEasy International under the PChome group—became the country's first third-party payment provider hit by ransomware after the Settra group exfiltrated an archive trade press cites as ~3.5 million user records and 102GB of internal data.

What happened

According to United Daily News, Settra infiltrated Pi Wallet systems on June 10, 2026, stealing member data, transaction logs, nine years of operational records, HR/payroll documents, and system architecture files. Settra labeled the victim "PChome" on its leak site, but reporting and company statements indicate the payment/fintech stack (Pi Wallet, Pi PayLink, PayEasy) bore the brunt—not PChome's core storefront.

What Pi Wallet and PChome said

Pi Wallet confirmed receiving a ransom demand, launched forensic investigation, notified Taiwan's Ministry of Digital Affairs (MODA), and pledged user notification once scope is confirmed. PChome said external dark-web posts were not directly tied to its main platform and that core operations showed no direct compromise.

Regulator response

MODA's digital-industry agency scheduled an on-site administrative inspection July 1, 2026 to review personal-data protection practices and may impose fines under Taiwan's Personal Data Protection Act if violations are found.

Who is at risk

Pi Wallet users face elevated phishing and OTP-interception fraud—attackers with transaction metadata can craft convincing payment, refund, or KYC messages. Dentists and merchants in adjacent PChome fintech units should also monitor payroll-themed lures if HR files were exfiltrated as reported.

Action items

  1. Do not download leak archives from criminal sites.
  2. Ignore SMS/email citing real Pi Wallet transactions unless verified in the official app.
  3. Rotate Pi Wallet passwords and enable any available MFA after official notice.
  4. Report fraud to Taiwan's 165 anti-fraud hotline if impersonation cites leaked transaction details.

Canonical record: Pi Wallet Settra 2026 on BreachHistory · Parent index: PChome Settra 2026.