Fraud Prevention Technology Company · E-commerce fraud screening and chargeback protection · E-commerce fraud prevention platform · USA
E-commerce fraud screening and chargeback protection service.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
In January 2023, Eye4Fraud, an e-commerce fraud-prevention/order-verification service, suffered a data breach; the data was listed for sale on a hacking forum in February 2023 and added to Have I Been Pwned. It contained ~16 million unique email addresses across ~147 tables (~65GB), including names and bcrypt password hashes for users, and names, phone numbers, physical addresses, and partial credit-card data (card type and last four digits) for orders. Full card numbers were not exposed. Affected individuals are largely merchants' end customers who never directly used Eye4Fraud. (NOTE: display count corrected from 525K to ~16M per HIBP; prior "full credit card" corrected to partial.)
Full threat analysis, exploitation vectors, and principal guidance below.
10 additional sections · verified field analysis · defensive doctrine
16.0M records analyzed
Eye4Fraud is a fraud-prevention / order-verification service for e-commerce merchants, screening online orders to reduce chargebacks and fraud. It processes merchant end-customer identity, contact, order, and payment-adjacent data.
Fraud-prevention platforms collect customer identity, transaction records, device and behavioral signals, chargeback histories, merchant data, and risk-scoring inputs across e-commerce screening workflows.
In February 2023, data attributed to Eye4Fraud was listed for sale on a hacking forum and added to Have I Been Pwned. The dataset spanned tens of millions of rows (147 tables, ~65GB), and Eye4Fraud (a fraud-prevention firm) faced criticism for the exposure.
The breach exposed identity, contact, and order data, including bcrypt-hashed passwords and partial credit-card details (card type + last four), for merchants' end customers who never directly interacted with Eye4Fraud. This enables targeted phishing, order/payment-themed scams, and credential-stuffing (password hashes), though full card numbers were not exposed. There is notable irony in a fraud-prevention vendor leaking customer data.
• Credential stuffing against reused passwords (bcrypt) | • Order/payment-themed phishing referencing real purchases | • Partial-card-enabled social engineering (last 4 + name) | • SIM-swap targeting using phone numbers | • Doxxing from exposed addresses
A consumer-service breach: contact and account data supports phishing, account takeover and profile enrichment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation