Threat Actor: Unknown | Unknown
Victim: Leal.co | Leal.co
Price: Not disclosed
Exfiltrated Data Type: Transaction records and customer ratings
Key Points :
- The breach allegedly occurred in August 2024.
- Over 1.42 million transaction records and 185,000 customer ratings were exposed.
- Compromised data includes customer names, identification numbers, transaction dates, ratings, and comments.
- Data structure includes fields such as “branch,” “name,” “ID,” “rating,” “transaction date,” “comments read,” and “response message.”
- Additional fields in the data structure include “date,” “city,” “cashier,” “user,” “type,” “prize,” “amount,” “points,” “invoice,” and “PIN.”
A threat actor has claimed responsibility for a data breach affecting Leal.co, a company linked to Texaco El Salvador. The breach, allegedly occurring in August 2024, exposed over 1.42 million transaction records and 185,000 customer ratings. The compromised data includes customer names, identification numbers, transaction dates, ratings, and comments.
As a sample, the data structure contains fields such as “branch,” “name,” “ID,” “rating,” “transaction date,” “comments read,” and “response message”:
"branch"; "name"; "ID"; "rating"; "transaction date"; "rating category"; "comment"; "response message""date"; "city"; "branch"; "cashier"; "user"; "ID"; "type"; "prize"; "amount"; "points"; "invoice"; "PIN"; "products"

The post A Threat Actor Claims to Sell Data of Leal.co appeared first on Daily Dark Web.