ConfirmedData breach

Woflow: a data breach

In March 2026, the AI-driven merchant data platform Woflow was named as a victim by the ShinyHunters data extortion group . The group subsequently published tens of thousands of files allegedly obtained from the company, comprising more than 2TB of data. The trove included hundreds of thousands of email addresses, names, phone numbers and physical addresses, with the data indicating it related to Woflow customers and, in turn, the customers of merchants using their platform.

The record

Organisation
Woflow
Identity
Woflowidentified by its domain in a verified breach record
Records affected
447,593 records
Data exposed
Email addresses, Names, Phone numbers, Physical addresses
Sector
Not recorded
Occurred
2026-03-04
Disclosed
2026-05-07
First recorded here
2026-09-09

Sources (1)

One source so far.

  1. Have I Been PwnedFirst reported

    2026-05-07