PChome, a well-known e-commerce company in Taiwan, suffered a serious security breach. The hacker group Settra recently publicly named PChome, the leading e-commerce company in Taiwan, on the dark web, claiming that it had invaded its webpage and payment system on June 10 and stolen up to 102GB of internal data, covering about 3.5 million users’ personal information, employee ID numbers and salaries, nine years of operating records, and anti-money laundering (AML) and other compliance documents. PChome’s third-party payment service “PiPai Wallet” operated by PaiFu International has confirmed that it has received the extortion message and reported it to the Digital Development Department of the competent authority. If the incident is ultimately confirmed to be true, Pi Wallet will become the first third-party payment operator in Taiwan to be invaded by ransomware.

PChome’s Pi wallet was hacked by the Settra hacker group, and all 3.5 million users’ personal information may have been leaked
Settra released a 12-page “Complete Penetration Report”, the attack scope far exceeds e-commerce platforms
Ransomware intelligence website Ransomware.live pchome.com.tw has been included in Settra’s victim list. The page indicates that the discovery time was 7:50 pm on June 28, 2026. It is estimated that the attack occurred on June 10.

Settra published a 12-page “Complete Penetration Report” on the dark web, detailing the intrusion steps, access paths and stolen data. The types of data disclosed in the report are extremely wide, including not only member information and transaction records, but also extending to employee personnel information, ID card numbers, salary information and a large number of resume documents. More importantly, the document also mentions API connection technical documents, production environment database architecture, internal audit and information security reports, and anti-money laundering (AML) compliance documents.

According to analysis by security industry players, the scope of this attack is not limited to the e-commerce platform itself, but also targets the overall payment and cash flow ecosystem of PChome, covering services such as PayLink, Pi Wallet, and PayLink. The core of the impact lies in the third-party payment and cash flow integration link, rather than a single consumption platform.
Information security experts pointed out that if member information, technical documents, compliance records and nine years of operational information are indeed obtained at the same time, it means that the attacker may not only have accessed a certain database, but also gradually pieced together the overall operating logic of the enterprise. What was stolen was not just 3.5 million records, but a complete map that allowed attackers to understand how the company worked.
Settra: A new ransomware organization emerging in 2026, using “investigation reports” to replace ransom letters
Settra is a new ransomware organization that emerged in 2026. Its operation mode adopts a typical double extortion strategy (Double Extortion). It first steals data while encrypting enterprise systems, and then uses public information as a means of pressure.

Different from traditional ransomware organizations, Settra prefers to “document” the attack process and release it to the public in a manner similar to an investigation report, describing the intrusion process and data content in detail. This approach not only increases the pressure of extortion, but also has an additional impact on the corporate brand and compliance image, extending the incident from “data security issues” to “corporate governance issues.”
Settra chose to use an investigation report instead of a ransom note. The more complete the format, the stronger the warning effect. This is a new threat method that uses corporate transparency as a weapon.
PChome responded: The main website has not been invaded, and the PiPai wallet is under independent operation and verification.
PChome’s parent company, Internet Home (PChome), publicly responded that no signs of intrusion were found in the parent company’s operating system. PiPai Wallet is an independently operated third-party payment service, and its information security and system management mechanisms are reviewed and audited by the operations team in accordance with existing procedures.
However, Paifu International has confirmed that it received a blackmail message from Settra and sent it on June 30formal statement. The statement noted that the company has taken the following actions:
- Activate information security response procedures: Conduct comprehensive system testing and forensic investigation together with information security experts
- Strengthen system monitoring: Real-time monitoring of any abnormal access behavior to prevent subsequent damage from expanding.
- Notify the competent authority: Report this incident to the Digital Development Department in accordance with the law
- Entrust third party forensics: Hire an independent information security forensics agency to verify the scope of the incident
Paifu International stated that it will proactively notify affected users after confirming the affected scope, and apologize to users who may be affected.
Follow-up risks: It is not just a one-time leak, but may also be the starting point of long-term penetration.
Judging from the information that has been disclosed so far, the key to this incident is not the “amount of leaked data”, but the type and correlation of the stolen data. Information security experts believe that once this kind of information is exploited, subsequent risks usually do not appear immediately, but may be transformed into more precise phishing attacks, business email fraud (BEC), or even supply chain penetration or long-term latent attacks.
In particular, if subsequent investigations confirm that unauthorized access has occurred, the scope of the impact may not be limited to a single operator, but may extend to third-party payment, bank cooperation systems, and the entire financial technology ecological chain.
User self-protection: change password immediately and pay attention to abnormal transactions
For users who have used PChome or Pi wallet, experts recommend taking the following self-protection measures:
- Change password: Change the same login password as PChome and Pi wallet as soon as possible
- Avoid password sharing: Different platforms should use different passwords to prevent credential stuffing attacks.
- Check accounts: Pay attention to whether there are any abnormal transactions in credit cards and bank accounts
- Beware of scams: Paifu International emphasizes that the company will never ask users to provide passwords, verification codes or financial account information via phone calls, text messages or emails.
The international customer service hotline of Paifu is 02-27035198 (Monday to Friday 09:00–18:00), and the official customer service email is service@piapp.com.tw.