• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - PChome’s Pi wallet was hacked by the Settra hacker group, and all 3.5 million users’ personal information may have been leaked

PChome’s Pi wallet was hacked by the Settra hacker group, and all 3.5 million users’ personal information may have been leaked

KOCPC Editor by KOCPC Editor
July 1, 2026 - Updated on August 5, 2026
in Anti-Virus Software and Internet Security, Latest Technology News

PChome, a well-known e-commerce company in Taiwan, suffered a serious security breach. The hacker group Settra recently publicly named PChome, the leading e-commerce company in Taiwan, on the dark web, claiming that it had invaded its webpage and payment system on June 10 and stolen up to 102GB of internal data, covering about 3.5 million users’ personal information, employee ID numbers and salaries, nine years of operating records, and anti-money laundering (AML) and other compliance documents. PChome’s third-party payment service “PiPai Wallet” operated by PaiFu International has confirmed that it has received the extortion message and reported it to the Digital Development Department of the competent authority. If the incident is ultimately confirmed to be true, Pi Wallet will become the first third-party payment operator in Taiwan to be invaded by ransomware.

PChome’s Pi wallet was hacked by the Settra hacker group, and all 3.5 million users’ personal information may have been leaked

Settra released a 12-page “Complete Penetration Report”, the attack scope far exceeds e-commerce platforms

Ransomware intelligence website Ransomware.live pchome.com.tw has been included in Settra’s victim list. The page indicates that the discovery time was 7:50 pm on June 28, 2026. It is estimated that the attack occurred on June 10.

Settra published a 12-page “Complete Penetration Report” on the dark web, detailing the intrusion steps, access paths and stolen data. The types of data disclosed in the report are extremely wide, including not only member information and transaction records, but also extending to employee personnel information, ID card numbers, salary information and a large number of resume documents. More importantly, the document also mentions API connection technical documents, production environment database architecture, internal audit and information security reports, and anti-money laundering (AML) compliance documents.

According to analysis by security industry players, the scope of this attack is not limited to the e-commerce platform itself, but also targets the overall payment and cash flow ecosystem of PChome, covering services such as PayLink, Pi Wallet, and PayLink. The core of the impact lies in the third-party payment and cash flow integration link, rather than a single consumption platform.

Information security experts pointed out that if member information, technical documents, compliance records and nine years of operational information are indeed obtained at the same time, it means that the attacker may not only have accessed a certain database, but also gradually pieced together the overall operating logic of the enterprise. What was stolen was not just 3.5 million records, but a complete map that allowed attackers to understand how the company worked.

Settra: A new ransomware organization emerging in 2026, using “investigation reports” to replace ransom letters

Settra is a new ransomware organization that emerged in 2026. Its operation mode adopts a typical double extortion strategy (Double Extortion). It first steals data while encrypting enterprise systems, and then uses public information as a means of pressure.

Different from traditional ransomware organizations, Settra prefers to “document” the attack process and release it to the public in a manner similar to an investigation report, describing the intrusion process and data content in detail. This approach not only increases the pressure of extortion, but also has an additional impact on the corporate brand and compliance image, extending the incident from “data security issues” to “corporate governance issues.”

Settra chose to use an investigation report instead of a ransom note. The more complete the format, the stronger the warning effect. This is a new threat method that uses corporate transparency as a weapon.

PChome responded: The main website has not been invaded, and the PiPai wallet is under independent operation and verification.

PChome’s parent company, Internet Home (PChome), publicly responded that no signs of intrusion were found in the parent company’s operating system. PiPai Wallet is an independently operated third-party payment service, and its information security and system management mechanisms are reviewed and audited by the operations team in accordance with existing procedures.

However, Paifu International has confirmed that it received a blackmail message from Settra and sent it on June 30formal statement. The statement noted that the company has taken the following actions:

  • Activate information security response procedures: Conduct comprehensive system testing and forensic investigation together with information security experts
  • Strengthen system monitoring: Real-time monitoring of any abnormal access behavior to prevent subsequent damage from expanding.
  • Notify the competent authority: Report this incident to the Digital Development Department in accordance with the law
  • Entrust third party forensics: Hire an independent information security forensics agency to verify the scope of the incident

Paifu International stated that it will proactively notify affected users after confirming the affected scope, and apologize to users who may be affected.

Follow-up risks: It is not just a one-time leak, but may also be the starting point of long-term penetration.

Judging from the information that has been disclosed so far, the key to this incident is not the “amount of leaked data”, but the type and correlation of the stolen data. Information security experts believe that once this kind of information is exploited, subsequent risks usually do not appear immediately, but may be transformed into more precise phishing attacks, business email fraud (BEC), or even supply chain penetration or long-term latent attacks.

In particular, if subsequent investigations confirm that unauthorized access has occurred, the scope of the impact may not be limited to a single operator, but may extend to third-party payment, bank cooperation systems, and the entire financial technology ecological chain.

User self-protection: change password immediately and pay attention to abnormal transactions

For users who have used PChome or Pi wallet, experts recommend taking the following self-protection measures:

  • Change password: Change the same login password as PChome and Pi wallet as soon as possible
  • Avoid password sharing: Different platforms should use different passwords to prevent credential stuffing attacks.
  • Check accounts: Pay attention to whether there are any abnormal transactions in credit cards and bank accounts
  • Beware of scams: Paifu International emphasizes that the company will never ask users to provide passwords, verification codes or financial account information via phone calls, text messages or emails.

The international customer service hotline of Paifu is 02-27035198 (Monday to Friday 09:00–18:00), and the official customer service email is service@piapp.com.tw.

Source, KOCPC Chinese

Tags: dark webhackerInformation securityPCHOMESettra

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed Xuanjie O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology