Eye4Fraud data breach (2023): was your email exposed?

Eye4Fraud (eye4fraud.com) suffered a data breach in January 2023 that exposed around 16 million accounts. The leaked records included email addresses, ip addresses, names, partial credit card data, passwords and phone numbers and more. Check whether your email was caught up in it — and lock down your accounts before the data is misused.

Check if my email was exposed — free →
Breach date
2023
Accounts exposed
16 million
Website
eye4fraud.com

What is Eye4Fraud, and why does it hold your data?

Almost nobody caught up in this one recognises the name, and that is the whole point of the company. Eye4Fraud sells fraud screening to online stores: a shop plugs it into checkout, and every order runs through Eye4Fraud's review before it ships, with the company advertising chargeback protection to the merchant if it approves an order that turns out to be fraudulent. Its customers are retailers. You were never its customer, and there is no Eye4Fraud account of yours to log into.

So the leaked records are not sign-ups. They are order-verification data handed over by shops you bought from — the details a merchant passes on to have a purchase checked. That matches what the exposed set contains: names, email addresses, phone numbers, physical addresses, IP addresses and partial card data, across roughly 16 million records dated January 2023. Passwords appear in the set as well, and wherever they came from, any password of yours sitting in a leaked file should be treated as burned everywhere you reused it.

This changes what is worth doing. There is no account to secure and nothing to delete at the source, so the useful moves are on your side of the transaction: watch the card statements for the cards you shopped with around that period, and be sceptical of emails or calls that quote a real past order back at you. Details that once proved a caller was legitimate — an order, a delivery address, the last four digits of a card — prove nothing once they are in a file that circulates.

What happened in the Eye4Fraud breach?

Eye4Fraud (eye4fraud.com) was hit by a data breach dated January 2023, exposing around 16 million accounts. Incidents like this happen when attackers break into a company’s user database, or when a misconfigured server or third-party partner leaks it — and the stolen records then spread among other criminals.

The exposed records included email addresses, ip addresses, names, partial credit card data, passwords, phone numbers and physical addresses. Leaked data doesn’t simply disappear: it gets copied, sold and re-posted across breach forums and dark-web markets for years. That’s why your information from the Eye4Fraud breach can still be abused long after the original incident — and why checking your exposure and locking down your accounts matters even now.

What data was exposed in the Eye4Fraud breach?

The Eye4Fraud breach exposed email addresses, ip addresses, names, partial credit card data, passwords, phone numbers and physical addresses. The more of these are tied to you, the more ways an attacker can impersonate you or break into your other accounts.

Email addressesIP addressesNamesPartial credit card dataPasswordsPhone numbersPhysical addresses

How the leaked Eye4Fraud data can be used against you

Because the Eye4Fraud breach exposed email addresses, ip addresses, names, partial credit card data, passwords and phone numbers and more, the leaked passwords let attackers try the same login on your other accounts (credential stuffing), so any site where you reused it is at risk; your email address becomes a target for convincing phishing, often referencing this very breach to look legitimate; your phone number fuels scam calls and smishing (fraudulent texts); and exposed payment details raise the risk of fraudulent charges.

How to check if you were affected

The leaked records themselves aren’t published openly, so the way to know is to check your email against known breach and dark-web databases. Our free tool does exactly that in a few seconds — no account needed.

Check my email against known breaches — free →

What to do if your Eye4Fraud account was breached

These steps are prioritized for exactly the kind of data the Eye4Fraud breach exposed.

1
Treat any password in this set as burned

There is no Eye4Fraud account of yours to reset, but the set carries passwords — so change any password of yours that could be in it everywhere you used it, starting with email and banking. Reused passwords are how one leaked file turns into a chain of account takeovers; a password manager makes giving each account its own painless.

2
Turn on two-factor authentication

Add 2FA — ideally an authenticator app or a passkey rather than SMS — to your email, banking and other important accounts, so a stolen password alone can’t get in.

3
Watch your finances

Check bank and card statements for charges you don’t recognize, set up transaction alerts, and ask your bank to reissue any card that may have been exposed.

4
Expect spam calls and scam texts

Leaked numbers feed robocalls and smishing. Never act on an unsolicited call or text, enable your carrier’s spam filter, and remove your number from data-broker sites that resell it.

5
Limit your address exposure

Exposed addresses spread to people-search sites that anyone can look up. Opting out of data brokers makes your home harder to find and lowers your doxxing risk.

6
Watch for targeted phishing

Scammers reference real breaches to sound credible, so treat any email mentioning Eye4Fraud with suspicion, and never use a password-reset link you didn’t request — go to the site directly instead.

7
Monitor whether your data resurfaces

Leaked data is resold for years, so a one-time clean-up isn’t enough. Ongoing breach and dark-web monitoring tells you the moment your details reappear, so you can act before an account is misused.

Common questions

The Eye4Fraud breach, answered

What is Eye4Fraud?

Eye4Fraud is a US fraud-prevention company that screens orders for online stores, approving or flagging them before the merchant ships. Its customers are retailers rather than consumers, which is why people who find their details in this breach have usually never heard of it: their data reached Eye4Fraud through a shop they bought from, not through an account they created.

Was my email in the Eye4Fraud breach?

You can find out in seconds with our free breach and dark-web check — enter your email and it tells you whether it appears in the Eye4Fraud breach and other known incidents.

How many people were affected by the Eye4Fraud breach?

Around 16 million accounts appear in the Eye4Fraud breach. That is the number of records in known breach databases, which can differ from the number of people a company later notifies.

When did the Eye4Fraud breach happen?

The Eye4Fraud data breach is dated January 2023 and exposed roughly 16 million accounts. Note that breached data often surfaces and is resold long after the original date.

What data was exposed in the Eye4Fraud breach?

The exposed records included email addresses, ip addresses, names, partial credit card data, passwords and phone numbers and more. Around 16 million accounts were affected.

What should I do after the Eye4Fraud breach?

There is no account to secure, so start with the passwords: change any of yours that could be in the set, everywhere you reused it, and turn on two-factor authentication on email and banking. Then watch the card statements from that period, treat calls or emails quoting a real past order as suspect, and monitor whether your details resurface on the dark web.

Is there compensation for this breach?

Breaches this size often end in a class action, and a settlement can take a year or more to reach a claim form. If one opens for Eye4Fraud, it will be run by a court-appointed administrator and announced on the company’s own breach page — never through an unsolicited email asking you to confirm bank details. Our guide to breach settlement claims covers who qualifies, what a payout actually covers, and the deadlines that decide it, and the list of settlements taking claims now is checked against the administrators rather than copied off aggregators.

Was your email in the Eye4Fraud breach?

Check free in about a minute — then we’ll help you remove your exposed data and keep it monitored.

Run my free breach check →