2026 FLY (Korea) — exfilar Firebase claim; ~47.9M rows / 6.16M orders (unverified)
Data compromised
Actor-claimed 46.6GB / 47.9M rows: 11,629 delivery riders with resident registration numbers + plaintext passwords; 6.16M orders with customer GPS and apartment entry codes; restaurant payment-gateway keys. Unverified — recordsAffected uses 6160000 order count as best cited scale.
Technical writeup
Unverified forum sale claim — August 14, 2026. Dark Web Informer reported actor exfilar offering a complete live extraction of Korean delivery platform FLY (flyfly.co.kr) at ~47.9 million rows / 46.6GB for $60,000 XMR, attributing access to missing Firebase security rules. Claimed contents include rider national IDs with plaintext passwords, millions of customer orders with GPS and building entry codes, and restaurant payment keys. FLY had not publicly confirmed at indexing. BreachHistory indexes recordsAffected 6160000 as the actor-cited order count labeled unverified.
Root cause
Forum actor exfilar claims absent Firebase rules left Firestore/Cloud Storage readable and writable without authentication