Spanish technology retailer PcComponentes denied claims that attackers stole a customer database affecting roughly 16 million users after a threat actor, “daghetiaw,” alleged theft of 16.3 million records, leaked a sample (reported as ~500,000 records), and offered the remainder for sale. The allegedly exposed data was described as including customer PII and commerce/support artifacts such as names, physical addresses, phone numbers, IP addresses, order details, wish-lists, and customer support messages (including exchanges via Zendesk). PcComponentes stated its investigation found no evidence of unauthorized access to its databases or internal systems and disputed the claimed scale, noting the number of active accounts is significantly lower; it also said it does not store customer passwords or financial details.
PcComponentes confirmed it experienced a credential stuffing attack, in which attackers attempt logins using reused email/password pairs sourced from other breaches. Threat intelligence firm Hudson Rock assessed the credentials likely originated from endpoints infected with info-stealing malware, aligning with the credential-reuse pattern. In response, PcComponentes implemented additional controls including CAPTCHA on login pages, mandatory 2FA for all accounts, and session invalidation requiring users to re-authenticate and enable 2FA.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In response to the account compromise activity, PcComponentes added CAPTCHA to login pages, required two-factor authentication for all accounts, and invalidated all active sessions. Customers were forced to re-authenticate and enable 2FA before regaining access.
PcComponentes said its investigation found no evidence of unauthorized access to its databases or internal systems and disputed claims that 16 million customers were affected. The company confirmed instead that it had experienced a credential stuffing attack affecting a small number of accounts.
Threat intelligence firm Hudson Rock assessed that the credentials in the leaked sample likely came from infostealer-malware infections rather than a direct breach of PcComponentes. It noted that some of the email addresses appeared in existing infostealer logs dating back to 2020.
A threat actor using the name "daghetiaw" claimed to possess 16.3 million PcComponentes customer records, leaked a sample of about 500,000 records, and offered the remaining data for sale. The sample allegedly contained customer, order, and Zendesk support-related information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.