A forum seller is advertising what they call a live breach of SwyftStore, the automated-retail platform behind smart vending machines for 28 brands including Pokémon Center, CVS Pharmacy, Best Buy and Disney: an open Google Firebase backend, 206,092 email addresses, payment-card hashes, receipts and source code. Ransomnews reviewed the published sample. The data is genuine Zoom Systems / Swyft automated-retail data. It is not from 2026. Every timestamp in it lands in 2016 and 2017.
A note on what we are publishing. This dataset contains real people’s email addresses, payment-card hashes, masked card receipts and administrator details. We reproduce none of it. Our analysis is statistical: counts, validation rates, timestamp decoding and distributions across the seller’s 1,000-record sample, never individual records. We do not link the sample, do not carry the seller’s download link or contact, and we did not attempt to access the reportedly open Firebase backend. Probing a third party’s cloud project would be unauthorised access.

What the seller is claiming
The pitch is that a US automated-retail SaaS left its entire Google Firebase ecosystem wide open, no auth, no token, and that a scraping pipeline pulled the lot: 52 top-level database nodes, 71 sibling projects, three production applications’ source code, and live credentials to the backend that runs the machine fleet. The seller lists 206,092 unique emails, 70,546 SHA256 payment-card hashes tagged by network, 59,797 masked-PAN receipts from the queue system, 8,545 sales transactions, and 217 vending machines across 28 brands in the US, Japan, Australia and Italy. The receipts are described as the crown jewel, and a “Live Access Status” block dated 8 August 2026 claims the backend is still reachable today.
It is a lot of confident detail, and the underlying platform is real. SwyftStore, formerly Zoom Systems, is one of the larger automated-retail operators, the company behind branded vending machines and kiosks in airports and malls. So the question is not whether the company exists. It is whether this data is what the listing says it is, and when it is from.

Some of it is real
The product data checks out. The Pokémon Center section carries real product names, prices, and UPC barcodes, and most of those UPCs pass the barcode check-digit test, which is what you see when the catalog came out of a real point-of-sale system rather than being typed up. The 28 brand organisation records list real corporate addresses: Google at 1600 Amphitheatre Parkway, Disney in Glendale, PopSockets in Boulder, Juul in San Francisco. The brand roster itself, Best Buy, Nespresso, Proactiv, Benefit, Pokémon Center, is exactly the set of names Zoom Systems ran automated stores for. None of that is invented.
So this is not a fabricated dataset. It is a real export from a real automated-retail backend. That is the part the seller gets right, and it is why the listing reads as credible on a first pass.

But it is from 2016, not 2026
Here is where the “live 2026 breach” framing falls apart. Every transaction in the sample carries an embedded timestamp inside its ID, a millisecond clock value that is trivial to read back into a date. We decoded all 200 of them. They run from 1 November 2016 to 15 January 2017, and nothing later. The Firebase record identifiers tell the same story: a genuine Firebase push ID encodes the moment it was created, and the ones in the receipts decode to October 2016. Not a single record in the sample was created after early 2017.
That fits the history exactly. Swyft acquired Zoom Systems in late 2017, and the brand set in this data, along with the Firebase stack it sits on, is the Zoom Systems platform of that era. A live 2026 export would be full of recent transactions. This one stops nine years ago. What is being sold as a current breach is an old Firebase dataset from 2016 and 2017, relabelled with this year’s date.
| Claim in the listing | What the sample shows | Our reading |
|---|---|---|
| Real automated-retail data | Valid product UPCs, real brand records and corporate addresses, genuine Firebase structure | Supported |
| “Current 2026” / live breach | All 200 embedded timestamps fall in Nov 2016 to Jan 2017; Firebase IDs decode to 2016 | Contradicted |
| 206,092 customer emails | 91 percent are smtp-relay envelope addresses, not people; roughly 17,500 look like real mailboxes | Heavily inflated |
| 70,546 payment-card hashes | Correct 64-character SHA256 format, but unverifiable as real cards | Unverifiable |
| Masked-PAN receipts | The sampled PANs are almost all Amex, JCB and Diners, with no Visa or Mastercard | Unusual for US retail |
| A full card number is included | The one provided starts with 1 and fails the Luhn check | Not a valid card |
The numbers do not hold up either
The headline figure is 206,092 email addresses. When you look at where they come from, 188,566 of them, about 91 percent, are addresses at a single SMTP relay domain used by a transactional email service. Those are envelope and bounce addresses from mail-sending logs, not customers. Strip them out and you are left with roughly 17,500 real-looking mailboxes. The “206,092 unique customer emails” is true only as a raw row count, and it is padded almost tenfold with machine noise.
The card data has its own tells. The masked receipts in the sample are dominated by American Express, JCB and Diners numbers with no Visa or Mastercard at all, which is not what a real US vending-machine customer base looks like. And the one place the listing promises a full card number, the actual value starts with a 1 and fails the standard checksum every real card passes. It is not a card. The payment package is not as complete or as current as the pitch implies.

Who is exfilar?
The seller, handle exfilar, is a VIP forum member who joined in April 2026, with around 20 posts and a modest positive reputation. The account is real enough, but the pattern is familiar: take a genuine old dataset, wrap it in fresh, technical-sounding copy, a named exfiltration pipeline, a live-access timestamp, a brute-force walkthrough for the card hashes, and list it as this year’s breach. The details that sound like inside knowledge are mostly restatements of what open Firebase misconfigurations expose in general.
It works well enough that it has already been picked up. At least one breach-alert service has written this up as a current 2026 incident, repeating the 206,092 emails and the 28 brands without noting that the records are a decade old. That is the gap this kind of listing relies on: the numbers get republished before anyone reads the dates.

Does a 2016 exposure still matter?
Some of it, yes. Real email addresses do not expire, and the roughly 17,500 genuine mailboxes here can still be folded into credential-stuffing and phishing lists. Unsalted SHA256 card hashes tied to a known BIN and last four digits are, as the seller correctly notes, brute-forceable offline, so even a decade later the hashed card data carries some residual risk. And if the Firebase backend really is still reachable, which we did not test and will not, then an abandoned but exposed project is something SwyftStore should close regardless of how old the records are.
What it is not is a fresh compromise of 206,092 people in 2026. Reporting it that way, as the first write-ups have, overstates the exposure and rewards the relabelling. The accurate version is narrower: a genuine but nine-year-old automated-retail dataset, thin on real customer emails and short one real card number, is being marketed as a live breach.
What to take from this
Two questions settle most listings like this, and they are the same two every time: is the data real, and is it new. Here the answer is yes and no. The catalogs, brand records and Firebase structure say the data is genuine. The timestamps say it is from 2016. When a listing leads with a live-access banner and a current year but every record inside it is nine years old, the year on the label is the marketing, and the dates in the data are the story.
We approached this the way we approach every listing on Ransomtracker: assume the seller is exaggerating, then check what they handed over. SwyftStore has not commented, and we will update this article if that changes. We are not publishing the sample, the download link or the contact details. Press contact for this piece is via the Ransomnews editorial team.
Frequently asked questions
Was Pokémon Center hacked?
Not directly. The data comes from SwyftStore, formerly Zoom Systems, the automated-retail company that ran branded vending machines for Pokémon Center and 27 other brands. Pokémon Center is one of the brands whose machine data appears in the set, not the breached party.
Is the SwyftStore vending data real?
The sample is genuine. Product catalogs carry valid barcode check digits, the brand records list real corporate addresses, and the Firebase structure is authentic. Authenticity is not the problem with this listing.
Is this a new 2026 breach?
The evidence says no. Every one of the 200 embedded timestamps in the sample falls between November 2016 and January 2017, and the Firebase record IDs decode to 2016. It is an old dataset marketed with a current date.
Were 206,092 customer emails really exposed?
Not as customer emails. About 91 percent are SMTP-relay envelope addresses from mail-sending logs, not people. Roughly 17,500 of the addresses look like real mailboxes.
Were credit card numbers leaked?
No full, valid card numbers appear in the sample. There are SHA256 card hashes and masked receipt records (first six and last four digits), and the one value labelled a full card number is not a valid card. The hashed data still carries some brute-force risk.
What is SwyftStore / Zoom Systems?
An automated-retail operator that builds and runs branded vending machines and kiosks in airports, malls and stores. Swyft acquired Zoom Systems in late 2017. The dataset predates or coincides with that period.
Does old leaked data still pose a risk?
Some. Email addresses and hashed card data do not fully expire, and an unsecured backend, if still open, remains a live exposure. But this is not a fresh compromise of hundreds of thousands of current customers, and should not be reported as one.
Sources and further reading
- Ransomnews Research Team analysis of the seller’s 1,000-record sample, 10 August 2026 (aggregate statistics only)
- Brinztech breach alert: SwyftStore Firebase exposure (the “live 2026” framing)
- Vending Market Watch: Swyft acquires Zoom Systems (2017)
- Zoom Systems (background)
- StealerCheck: look up whether an address appears in stealer logs
- Ransomtracker: live leak-site and listing tracker
