Cashback and rewards platform.
In September 2020, the Singapore-based cashback rewards platform ShopBack suffered a data breach exposing over 20 million unique email addresses along with names, phone numbers, country of residence, and passwords stored as salted SHA-1 hashes.
ObscureIQ assessment: High risk of fraud, account takeover, and transaction manipulation. Purchase behavior data enables targeted scams and profiling.
Salted SHA-1 credentials are crackable, exposing reused passwords to stuffing; contact data supports phishing across ShopBacks Southeast Asian user base.
Cashback and rewards platform.
Cashback and affiliate commerce platforms collect user accounts, emails, transaction data, purchase history, and financial reward balances tied to online shopping activity.
Field names are shown in full for clarity and search visibility. Canonical machine keys are emitted only in this page’s structured data.
If you believe your information may be included:
In September 2020, the Singapore-based cashback rewards platform ShopBack suffered a data breach exposing over 20 million unique email addresses along with names, phone numbers, country of residence, and passwords stored as salted SHA-1 hashes.
Verified fields include Email Address, Full Name, Geographic Location, Password, Phone Number.
Change reused passwords, enable MFA, and (if identity or financial data is involved) freeze your credit and monitor your accounts.
Every claim on this page is traceable. This breach draws on:
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation