← Pi Wallet (PayEasy International)

2026 Pi Wallet (PayEasy) — Settra ransomware; 3.5M user records; Taiwan's first ransomware-hit payment provider

2026 3.5M records affected Share on X

Data compromised

Trade press cites ~3.5M user records and 102GB archive: member profiles, transaction records, nine years of operational logs, HR/payroll/resume documents, and internal system architecture—Pi Wallet confirmed receiving a ransom demand and reported to MODA; PChome stated core e-commerce site not directly compromised

Technical writeup

Verified incident — reported June 30–July 1, 2026. Taiwan's United Daily News reported that Settra ransomware infiltrated PChome-affiliated Pi Wallet (Pi錢包 / PayEasy International) on June 10, 2026, exfiltrating approximately 102GB including roughly 3.5 million user records, internal architecture diagrams, HR and payroll files, and nine years of operational history. Settra published a 12-page penetration report on its leak site labeling the victim "PChome," though reporting indicates the core impact sits in the payment ecosystem (Pi Wallet, Pi PayLink, PayEasy, and related fintech units) rather than PChome's main storefront. Pi Wallet issued a statement confirming it received a ransom message, engaged forensic experts, notified Taiwan's Ministry of Digital Affairs, and will notify users once scope is finalized; PChome said its primary site showed no direct compromise. MODA's digital-industry agency scheduled on-site administrative inspection July 1, 2026. This is Taiwan's first publicly disclosed ransomware incident against a third-party payment provider. See also pchome-settra2026 for parent e-commerce indexing.

Root cause

Settra ransomware group exfiltration of Pi Wallet (拍付國際) payment systems on June 10, 2026; Taiwan Ministry of Digital Affairs (MODA) administrative inspection July 1, 2026

References