In late March 2022, the Sri Lankan payment gateway PayHere suffered a data breach that exposed more than 65GB of payment records including over 1.5M unique email addresses. The data also included IP and physical addresses, names, phone numbers, purchase histories and partially obfuscated credit card data (card type, first 6 and last 4 digits plus expiry date). A month later, PayHere published a blog on the incident titled Ensuring Integrity on PayHere Cybersecurity Incident.
Accounts breached: 1580249
Breached on: March 27, 2022
Exposed data: Email addresses, IP addresses, Names, Partial credit card data, Phone numbers, Physical addresses, and Purchases
Added on: May 02, 2022