Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

Pokémon Center vending ‘breach’ is old 2016 data

Ransomnews Research TeamBy Ransomnews Research TeamAugust 10, 2026No Comments11 Mins Read19 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Ransomnews cover: Swyft vending data marketed as a live 2026 breach, but every record in the sample dates from 2016
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

A forum seller is advertising what they call a live breach of SwyftStore, the automated-retail platform behind smart vending machines for 28 brands including Pokémon Center, CVS Pharmacy, Best Buy and Disney: an open Google Firebase backend, 206,092 email addresses, payment-card hashes, receipts and source code. Ransomnews reviewed the published sample. The data is genuine Zoom Systems / Swyft automated-retail data. It is not from 2026. Every timestamp in it lands in 2016 and 2017.

// KEY FACTS

Threat actor
exfilar (data-leak forum vendor)
Victim
SwyftStore / Zoom Systems (automated-retail SaaS) · Automated retail / SaaS · United States (global brands)
Timeline
Attack: Not established; every timestamp in the sample is 2016-2017  ·  Disclosed: 2026-08-08
Data claimed
Seller claims a full Firebase export (~1.8 GB raw): 206,092 email rows, 70,546 card hashes, 59,797 masked-PAN receipts, 8,545 transactions, 217 kiosks, 28 brands · Product catalogs, brand organisation records, SHA256 card hashes, masked-PAN receipts, email addresses, admin and customer PII, sales transactions, source-code references
Ransom status
Offered for sale; download link and contact withheld by Ransomnews
Verification
Ransomnews reviewed the seller's 1,000-record sample. Product catalogs carry valid UPCs and the brand records are genuine Zoom/Swyft data. But all 200 embedded timestamps decode to October 2016 to January 2017, and the one genuine Firebase push ID resolves to 2016, so this is aged data, not a live 2026 breach. 91 percent of the 206,092 emails are SMTP-relay envelope addresses rather than customers, and the single full card number provided is not a valid card. SwyftStore has not commented.

A note on what we are publishing. This dataset contains real people’s email addresses, payment-card hashes, masked card receipts and administrator details. We reproduce none of it. Our analysis is statistical: counts, validation rates, timestamp decoding and distributions across the seller’s 1,000-record sample, never individual records. We do not link the sample, do not carry the seller’s download link or contact, and we did not attempt to access the reportedly open Firebase backend. Probing a third party’s cloud project would be unauthorised access.

Forum thread advertising a claimed breach of an automated-retail vending SaaS across 28 brands including Pokemon Center
The listing, posted on 8 August 2026. The record counts and brand list are the seller’s own.

What the seller is claiming

The pitch is that a US automated-retail SaaS left its entire Google Firebase ecosystem wide open, no auth, no token, and that a scraping pipeline pulled the lot: 52 top-level database nodes, 71 sibling projects, three production applications’ source code, and live credentials to the backend that runs the machine fleet. The seller lists 206,092 unique emails, 70,546 SHA256 payment-card hashes tagged by network, 59,797 masked-PAN receipts from the queue system, 8,545 sales transactions, and 217 vending machines across 28 brands in the US, Japan, Australia and Italy. The receipts are described as the crown jewel, and a “Live Access Status” block dated 8 August 2026 claims the backend is still reachable today.

It is a lot of confident detail, and the underlying platform is real. SwyftStore, formerly Zoom Systems, is one of the larger automated-retail operators, the company behind branded vending machines and kiosks in airports and malls. So the question is not whether the company exists. It is whether this data is what the listing says it is, and when it is from.

Seller's summary of the dataset size and compromised data types, with a masked card example redacted by Ransomnews
The seller’s own summary of the numbers and data types. We redacted the masked card example.

Some of it is real

The product data checks out. The Pokémon Center section carries real product names, prices, and UPC barcodes, and most of those UPCs pass the barcode check-digit test, which is what you see when the catalog came out of a real point-of-sale system rather than being typed up. The 28 brand organisation records list real corporate addresses: Google at 1600 Amphitheatre Parkway, Disney in Glendale, PopSockets in Boulder, Juul in San Francisco. The brand roster itself, Best Buy, Nespresso, Proactiv, Benefit, Pokémon Center, is exactly the set of names Zoom Systems ran automated stores for. None of that is invented.

So this is not a fabricated dataset. It is a real export from a real automated-retail backend. That is the part the seller gets right, and it is why the listing reads as credible on a first pass.

Seller's description of backend API credentials, source code and the 28 affected brands with corporate addresses
The backend, source-code and brand claims. The brand roster matches the names Zoom Systems ran stores for.

But it is from 2016, not 2026

Here is where the “live 2026 breach” framing falls apart. Every transaction in the sample carries an embedded timestamp inside its ID, a millisecond clock value that is trivial to read back into a date. We decoded all 200 of them. They run from 1 November 2016 to 15 January 2017, and nothing later. The Firebase record identifiers tell the same story: a genuine Firebase push ID encodes the moment it was created, and the ones in the receipts decode to October 2016. Not a single record in the sample was created after early 2017.

That fits the history exactly. Swyft acquired Zoom Systems in late 2017, and the brand set in this data, along with the Firebase stack it sits on, is the Zoom Systems platform of that era. A live 2026 export would be full of recent transactions. This one stops nine years ago. What is being sold as a current breach is an old Firebase dataset from 2016 and 2017, relabelled with this year’s date.

Claim in the listingWhat the sample showsOur reading
Real automated-retail dataValid product UPCs, real brand records and corporate addresses, genuine Firebase structureSupported
“Current 2026” / live breachAll 200 embedded timestamps fall in Nov 2016 to Jan 2017; Firebase IDs decode to 2016Contradicted
206,092 customer emails91 percent are smtp-relay envelope addresses, not people; roughly 17,500 look like real mailboxesHeavily inflated
70,546 payment-card hashesCorrect 64-character SHA256 format, but unverifiable as real cardsUnverifiable
Masked-PAN receiptsThe sampled PANs are almost all Amex, JCB and Diners, with no Visa or MastercardUnusual for US retail
A full card number is includedThe one provided starts with 1 and fails the Luhn checkNot a valid card
Ransomnews Research Team analysis of the seller’s 1,000-record sample, aggregates only, 10 August 2026.

The numbers do not hold up either

The headline figure is 206,092 email addresses. When you look at where they come from, 188,566 of them, about 91 percent, are addresses at a single SMTP relay domain used by a transactional email service. Those are envelope and bounce addresses from mail-sending logs, not customers. Strip them out and you are left with roughly 17,500 real-looking mailboxes. The “206,092 unique customer emails” is true only as a raw row count, and it is padded almost tenfold with machine noise.

The card data has its own tells. The masked receipts in the sample are dominated by American Express, JCB and Diners numbers with no Visa or Mastercard at all, which is not what a real US vending-machine customer base looks like. And the one place the listing promises a full card number, the actual value starts with a 1 and fails the standard checksum every real card passes. It is not a card. The payment package is not as complete or as current as the pitch implies.

Seller's list of affected entities and a claimed live Firebase access status dated August 8 2026
The affected-entities list and the claimed “Live Access Status” dated 8 August 2026. We did not test the backend.

Who is exfilar?

The seller, handle exfilar, is a VIP forum member who joined in April 2026, with around 20 posts and a modest positive reputation. The account is real enough, but the pattern is familiar: take a genuine old dataset, wrap it in fresh, technical-sounding copy, a named exfiltration pipeline, a live-access timestamp, a brute-force walkthrough for the card hashes, and list it as this year’s breach. The details that sound like inside knowledge are mostly restatements of what open Firebase misconfigurations expose in general.

It works well enough that it has already been picked up. At least one breach-alert service has written this up as a current 2026 incident, repeating the 206,092 emails and the 28 brands without noting that the records are a decade old. That is the gap this kind of listing relies on: the numbers get republished before anyone reads the dates.

Forum profile of the vendor exfilar, a VIP member who joined in April 2026
The seller’s profile: a VIP account that joined in April 2026.

Does a 2016 exposure still matter?

Some of it, yes. Real email addresses do not expire, and the roughly 17,500 genuine mailboxes here can still be folded into credential-stuffing and phishing lists. Unsalted SHA256 card hashes tied to a known BIN and last four digits are, as the seller correctly notes, brute-forceable offline, so even a decade later the hashed card data carries some residual risk. And if the Firebase backend really is still reachable, which we did not test and will not, then an abandoned but exposed project is something SwyftStore should close regardless of how old the records are.

What it is not is a fresh compromise of 206,092 people in 2026. Reporting it that way, as the first write-ups have, overstates the exposure and rewards the relabelling. The accurate version is narrower: a genuine but nine-year-old automated-retail dataset, thin on real customer emails and short one real card number, is being marketed as a live breach.

What to take from this

Two questions settle most listings like this, and they are the same two every time: is the data real, and is it new. Here the answer is yes and no. The catalogs, brand records and Firebase structure say the data is genuine. The timestamps say it is from 2016. When a listing leads with a live-access banner and a current year but every record inside it is nine years old, the year on the label is the marketing, and the dates in the data are the story.

We approached this the way we approach every listing on Ransomtracker: assume the seller is exaggerating, then check what they handed over. SwyftStore has not commented, and we will update this article if that changes. We are not publishing the sample, the download link or the contact details. Press contact for this piece is via the Ransomnews editorial team.

Frequently asked questions

Was Pokémon Center hacked?

Not directly. The data comes from SwyftStore, formerly Zoom Systems, the automated-retail company that ran branded vending machines for Pokémon Center and 27 other brands. Pokémon Center is one of the brands whose machine data appears in the set, not the breached party.

Is the SwyftStore vending data real?

The sample is genuine. Product catalogs carry valid barcode check digits, the brand records list real corporate addresses, and the Firebase structure is authentic. Authenticity is not the problem with this listing.

Is this a new 2026 breach?

The evidence says no. Every one of the 200 embedded timestamps in the sample falls between November 2016 and January 2017, and the Firebase record IDs decode to 2016. It is an old dataset marketed with a current date.

Were 206,092 customer emails really exposed?

Not as customer emails. About 91 percent are SMTP-relay envelope addresses from mail-sending logs, not people. Roughly 17,500 of the addresses look like real mailboxes.

Were credit card numbers leaked?

No full, valid card numbers appear in the sample. There are SHA256 card hashes and masked receipt records (first six and last four digits), and the one value labelled a full card number is not a valid card. The hashed data still carries some brute-force risk.

What is SwyftStore / Zoom Systems?

An automated-retail operator that builds and runs branded vending machines and kiosks in airports, malls and stores. Swyft acquired Zoom Systems in late 2017. The dataset predates or coincides with that period.

Does old leaked data still pose a risk?

Some. Email addresses and hashed card data do not fully expire, and an unsecured backend, if still open, remains a live exposure. But this is not a fresh compromise of hundreds of thousands of current customers, and should not be reported as one.

Sources and further reading

  • Ransomnews Research Team analysis of the seller’s 1,000-record sample, 10 August 2026 (aggregate statistics only)
  • Brinztech breach alert: SwyftStore Firebase exposure (the “live 2026” framing)
  • Vending Market Watch: Swyft acquires Zoom Systems (2017)
  • Zoom Systems (background)
  • StealerCheck: look up whether an address appears in stealer logs
  • Ransomtracker: live leak-site and listing tracker
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleIsraeli population registry for sale, but the data is old
Next Article Quake3 and morgot: tracing REvil’s source-code developer
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Quake3 and morgot: tracing REvil’s source-code developer

August 10, 2026

Israeli population registry for sale, but the data is old

August 10, 2026

Żabka confirms breach via supplier account, data for sale

August 3, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.