Leak of confidential information

BigBrother Reports an Attack on FamilyBox.Store

On May 11, 2026, a threat actor known as BigBrother posted on a dark web forum claiming to be selling 1,100,000 records of personally identifiable information (PII) from FamilyBox.Store, an online supermarket associated with the TEALCA Group. The compromised data reportedly includes customer IDs, names, email addresses, phone numbers, physical addresses, and order details. The threat actor provided sample data via a file-sharing link on ufile.io.

Overview

Missing evidence

The exact date of the breach is not specified; only the date the data was put up for sale is given.

Impact details

1,100,000 Exposed records

Forum posts and public reports attribute the alleged sale of 1,100,000 rows of PII from familybox.store to BigBrother; no official or independent confirmation was found.

personally identifiable informationcustomer recordscontact information

Classification & severity

Category
Information content security
Subtype
Leak of confidential information
Confidence
Medium

Severity assessment

High
Functional impact
None
Information impact
Personal data
Affected scope
Multiple users
Critical service
None
Public confidence
Moderate

Public evidence supports the existence of an alleged large-scale sale of personal data affecting FamilyBox.Store users, but this continues to be based on complaints or reports from the affected individuals themselves.

Data exfiltration· Claimed Confidentiality

Timeline

Claim

BigBrother listed FamilyBox.Store as an alleged victim.

Evidence & sources

4 sources