Hacker claims WooCommerce data breach, Automattic denies its systems were hit

Organization
WooCommerce (Automattic)
Exploit
Third-Party Data Breach
Industry
E-commerce Software

In early April 2025 a threat actor using the handle Satanic offered for sale on the BreachForums cybercrime site a dataset it said held 4,432,120 records tied to websites running WooCommerce, the open source e-commerce plugin for WordPress. The actor dated the theft to April 6 and the listing became public reporting on April 9.

The advertisement described roughly 1.3 million unique email addresses and about 998,000 unique phone numbers, alongside physical addresses, social media profiles and business metadata such as sales revenue, employee counts, domain authority rankings and technology stacks. Records said to belong to NVIDIA, Texas.gov and the National Institute of Standards and Technology were named among the contents.

The seller stated the data had not been taken from WooCommerce's core infrastructure but from systems associated with sites using the platform, including customer relationship management and marketing automation tools connected through third-party integrations.

Automattic, which owns WooCommerce, rejected the characterisation. The Woo team said it had investigated the data samples and compared them against its own records, and confirmed the data was not obtained in a breach of WooCommerce.com or any other Automattic service. It said the information appeared to have come from a third-party service that aggregates publicly accessible data about e-commerce stores. The record counts and contents rest on the seller's own claims and were not independently verified.

Sources