
UPS (Partial) Breach
Oct 10, 2025
29,618,000 rows
Added on Oct 3, 2025
What happened in the UPS (Partial) Breach?
DataBreach.com Team · October 2nd 2025, 8:00 pm EDT
The incident is one of several breaches affecting Salesforce in 2025. A group calling itself "Scattered LAPSUS$ Hunters" released a limited sample of the stolen database on October 3, 2025. The records have since been indexed and anonymized in our search engine.
According to the attackers, the full dataset is scheduled for release on October 10, 2025.
Data found in hackers’ sample -
🧍 Personal Information
- Full name - ✅ Present
- Email address - ✅ Present
- Phone number - ✅ Present
- Mailing address (street, city, state, ZIP, country) - ✅ Present
- Latitude / longitude - ✅ Present (in shipping address)
- Gender - ⛔ Empty
- Date of birth / age - ⛔ Empty
- Nationality / country of residence - ✅ Present (U.S. and Argentina)
🏢 Company / Business Information
- Account / company name - ✅ Present
- Industry - ✅ Present (“Not Available”)
- Website - ⛔ Empty (field exists in UPS account structure but none listed)
- Billing and shipping addresses - ✅ Present (Chicago, Illinois, U.S.)
- Account number - ✅ Present (UPS internal numeric ID)
- Business unit / division / region - ✅ Present (“US,” “Argentina,” “AMERICAS”)
- Department / title - ✅ Present (e.g., “Invoice Collector”)
- District / operating center - ✅ Present (“District 46,” “Argentina”)
- Customer segment - ✅ Present (“D4-Platform and Indirect”)
- Type of account - ✅ Present (“On Call Air,” “Customer”)
🪪 Identification Data
- Internal Salesforce IDs (Account, Contact, User) - ✅ Present
- Record type IDs - ✅ Present
- Account / customer number - ✅ Present
- Operating service center ID - ✅ Present
- Manager and owner IDs - ✅ Present
- External / government IDs - ⛔ Empty
📧 Contact Information
- Customer email - ✅ Present
- Employee email - ✅ Present
- Phone numbers (mobile, office) - ✅ Present
- Alternate phone numbers - ⛔ Empty
- Fax - ⛔ Empty
💬 Marketing & Communication Preferences
- Opt-out of email / fax / direct mail - ✅ Present (false across all)
- Promotional and newsletter preferences - ✅ Present (false)
- Service updates and regulatory change notifications - ✅ Present (false)
- Customer service contact flags - ✅ Present
- “Remove me from email communications” flag - ✅ Present (false)
- Email autoresponse preferences - ✅ Present (false)
⚙️ System Metadata
- Record creation and modification timestamps - ✅ Present
- Created by / last modified user IDs - ✅ Present
- SystemModstamp / sync timestamps - ✅ Present
- Currency codes - ✅ Present (“USD”)
- Owner and manager info - ✅ Present
- IsDeleted, IsPriorityRecord flags - ✅ Present (false)
- User locale, language, and timezone - ✅ Present
- Photo URLs and banner images - ✅ Present
- User role and profile - ✅ Present
- Login history - ✅ Present (dates and IDs)
👩💼 Employee / User Data
- Employee name - ✅ Present
- Username and alias - ✅ Present
- Title - ✅ Present (“Invoice Collector”)
- Region and district - ✅ Present
- Department / reporting manager - ✅ Present
- Active / inactive status - ✅ Present (inactive in this sample)
- Time zone, locale, language - ✅ Present
- Last login date - ✅ Present
- Email encoding and notification preferences - ✅ Present
- Partner / portal status - ✅ Present (false)
⚖️ Privacy & Legal Fields
- Opt-out and consent flags - ✅ Present (all false)
- Do-not-call and do-not-mail flags - ✅ Present (false)
- Marketing opt-ins - ✅ Present (false)
- No SSNs, payment data, or sensitive identifiers - ⛔ Empty
Recent News











RansomWho? Inside the Great Ransomware Splintering of 2026
18 hours ago

OpenAI Models Escaped a Cyber Test and Breached Major AI Platform Hugging Face
19 days ago

Ransomware negotiator stole at least $10M while selling out his own clients
20 days ago

Ho-ly G*t: TeamPCP Claims Theft of Thousands of GitHub Internal Repositories
3 months ago

17M Nissan cars impacted by large ransomware attack
4 months ago

Iranian hackers just used Stryker’s own security tools to delete itself
5 months ago

Massive Odido cyberattack leaks customer IBANs and government IDs
5 months ago

Figure breach proves blockchain cannot save us from human error
6 months ago

Substack notifies users of data breach affecting nearly 700,000 accounts
6 months ago

UPenn claims "Under 10" victims in 1.2M breach involving donors like Trump and Musk
6 months ago

How 0apt is Using Random Noise to Fake a Ransomware Empire
6 months ago