A forum user known as exfilar claims to be selling a complete live extraction from FLY’s backend after Firebase rules were left absent, making Firestore and Cloud Storage readable and writable without authentication. The alleged dump includes rider resident registration numbers, plaintext passwords, customer delivery details, payment credentials, and other sensitive records tied to flyfly.co.kr, but the claim remains unverified. #FLY #flyfly.co.kr #exfilar
Keypoints
- A seller named exfilar claims to have extracted FLY’s production backend.
- The alleged leak stems from missing Firebase rules and open write access.
- The dataset is said to contain 47.9 million rows and 46.6GB of data.
- Exposed records reportedly include rider IDs, plaintext passwords, and bank details.
- The listing also claims access to customer addresses, entry codes, and payment keys.
DarkWebInformer.com Providing intel from some of the darkest places on the Dark Web & Clearnet. Breaches, Darknet Markets, Ransomware, Threat Alerts, & more!