Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Hackers Put Alleged 86,900 H.V.M.N. Customer Records for Sale on Underground Forum

Hackers Put Alleged 86,900 H.V.M.N. Customer Records for Sale on Underground Forum

By: Morgan Cipher Senior Privacy Journalist

Last updated: August 6, 2026

Human Written
Hackers Put Alleged 86,900 H.V.M.N. Customer Records for Sale on Underground Forum
  • A threat actor claims to be selling an alleged H.V.M.N. customer database containing about 86,900 user profiles.

  • The listing claims the data includes customer contact details, shipping information, subscription records, and limited payment-related metadata. There is no public evidence confirming these claims.

  • H.V.M.N. hasn’t reported any security breach, and independent researchers have yet to validate the alleged data.

A cybercriminal has alleged that they have a customer database belonging to H.V.M.N., a San Francisco company that deals in ketone supplements and nutrition products.

The advert appeared on a cybercrime forum, and it stated that the database consists of about 86,900 records. The actor claims the information came from H.V.M.N.’s systems and is advertising the dataset to other criminals.

Right now, those claims are still just mere allegations without proof. H.V.M.N. hasn’t confirmed a breach, and no external cybersecurity experts have backed it up either. Also, there’s no forensic evidence or technical report out there to prove what the seller is saying.

What the Seller Claims the Data Contains

The underground post describes a dataset that allegedly includes both customer account information and order-related details.

According to the listing, the exposed information includes:

  • Customer names
  • Email addresses
  • IP addresses
  • Shipping addresses
  • Subscription identifiers
  • Stripe customer IDs
  • Account metadata

The seller also claims the database contains limited payment information. This includes masked payment card numbers, card expiration dates, billing ZIP codes, as well as shipping details.

Masked card numbers typically hide most digits and are generally not enough on their own to complete fraudulent card transactions. However, together with other personal information, the risk of phishing attacks, identity fraud, and targeted scams becomes higher.

The threat actor further claims the H.V.M.N. data is only one part of a broader campaign. They said they’ll release additional customer and event databases from other organizations in the future. Those claims have not been independently verified.

No Official Confirmation So Far

As of publication, H.V.M.N. has not issued a public statement confirming a cybersecurity incident or customer data breach. They also haven’t filed any breach notifications with regulators or public disclosures confirming the exposure of customer information.

Cybercriminals often post ads of stolen databases on dark web forums. Some listings often turn out to be authentic. However, many lists usually contain recycled information, outdated records, fabricated claims, or data from multiple unrelated sources.

For that reason, security researchers generally avoid treating forum listings as confirmed breaches. They conduct tests on sample data, confirm if there was an account compromise, or hear from the victim before making any assumptions.

In the absence of these pieces of information, it is difficult to tell if the alleged database is legitimate, partially accurate, or totally fake.

Why Customer Data Matters

If the allegation turns out to be true, the database holds enough info that cybercriminals could use to carry out highly convincing social engineering schemes.

People’s names, email addresses, mailing addresses, and subscriptions could enable attackers to craft highly believable phishing emails.

Stripe customer IDs, even though they are not payment details, could also provide attackers with an opportunity to craft targeted scams using the information stolen from other places.

While the description of the data speaks about masked payment card details, these data points alone would normally not let anyone purchase anything without permission. That makes even seemingly limited customer data valuable in underground markets.

The value of account access in underground markets is substantial. A dark web vendor is reportedly selling an alleged Snapchat account takeover kit for $350,000, reflecting how cybercriminals monetize compromised accounts

What Customers Should Do

Since nobody’s officially confirmed this breach yet, there’s really no proof that H.V.M.N. customers are in trouble. However, just because it’s not “official” doesn’t mean customers shouldn’t have their guard up. These kinds of leak rumors pop up all the time online, and being alert could save you a lot of heartbreak.

Therefore, here’s what customers can do right now. Monitor your inbox. If you begin receiving unsolicited emails asking you to reset your password, update your payment information, or “verify” your account, do not act on them just yet. And any email demanding your personal or payment info urgently? Best ignore it.

Also, avoid reusing one password on many accounts. Instead, make them unique. And if you’ve got the option to turn on two-factor authentication, do it. It adds an extra layer of security between your account and any would-be hacker. Last but not least, don’t forget to look over your financial statements and check your online accounts for any activity that doesn’t look right.

Presently, the alleged breach of H.V.M.N. remains what it is, a claim. Until updates verifying or disputing the claim surface, approach it with skepticism.

Share this article

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.