Weee! confirmed a breach after order data for 1.1 million customers leaked

Organization
Weee!
Exploit
Hacking
Industry
Retail

Weee!, an online grocery delivery service specialising in Asian and Hispanic products, confirmed a data breach in February 2023 after a threat actor using the name IntelBroker began posting its customer data on the Breached hacking forum.

The leaked dataset covered roughly 11.3 million orders. Troy Hunt of Have I Been Pwned told BleepingComputer it contained about 1.1 million unique email addresses, so the larger figure reflects repeat orders rather than distinct customers. Reporting that cited the attacker's own post initially described 11 million customers.

Exposed fields included first and last names, email addresses, phone numbers, physical addresses, device type, order numbers and order comments such as delivery instructions and apartment access codes. The affected orders were placed between July 12, 2021 and July 12, 2022.

Weee! said no customer payment data was exposed because it does not retain payment information in its databases. The company acknowledged the breach, said it had notified affected customers, and said it was carrying out a security review.

Sources