2025 VTEX — open shopper / order-style datastore (~6M individuals in press estimates); misconfiguration narrative
Data compromised
Names, contact and order-related shopper metadata in journalist and researcher summaries—field-level detail varies
Technical writeup
Investigative reporting in 2025 traced a large internet-exposed dataset of e-commerce shopper and transaction-oriented records to infrastructure described in headlines as tied to VTEX’s ecosystem, with independent researchers citing discovery around February 28, 2025, public attention in August, and coordinated takedown rhetoric into October. VTEX and partner messaging in coverage sometimes distinguished platform-owned databases from third-party deployments; BreachHistory indexes the incident as materially associated with the VTEX brand while noting attribution nuance in vendor statements.
Root cause
Internet-facing datastore / cloud object exposure attributed in press to configuration or governance failure on affiliated infrastructure