-
A darkweb actor named Evil_Zone claims to sell 12.5 million user records allegedly stolen from South Korean platform Zigzag.
-
The database listing indicates the names, email id’s, phone numbers, addresses, session tokens and the password hashes of users.
-
Experts in security say that the exposed records raise chances of credential stuffing, phishing frauds, theft of identity and extortion.

A cybercriminal is advertising a massive database of stolen personal information on a hidden darkweb forum. The seller claims the stolen file contains private details from twelve point five million account holders on zigzag.kr.
This platform operates as a major social network in South Korea for community discussions. Millions of active members use the service daily to post messages and connect with friends online.
Security monitoring groups are currently tracking the forum listing as the seller offers the dataset for trade. Users now face potential digital safety threats if investigators confirm the leak as genuine.
Details Inside the Exposed Database and Cyber Criminal Profile
A dark web post surfaced recently with shocking claims about a massive data security incident. The forum user offering the files goes by the online alias Evil_Zone. This seller previously built a reputation on illicit digital marketplaces like XForums.st for sharing large credential dumps.
Cybersecurity researchers note that this actor specializes in collecting stolen stealer logs and building massive combolists. Rather than running targeted ransomware operations, this individual focuses primarily on harvesting account login details in bulk.
The seller published a sample link along with a specific session ID to convince potential buyers. Furthermore, the listing outlines twenty-one distinct data fields contained within the stolen database.
Exposed details include unique ZIGZAGUUID identifiers, account usernames, full names, personal email addresses, and encrypted password hashes. In addition, the stolen records show account roles, membership status, gender, birth dates, and active phone numbers. The database also exposes physical addresses, postal codes, and specific reward points stored inside user profiles.
System timestamp records, like created at, updated at, and last login, appear throughout the sample dataset as well. However, technical teams have not yet verified the authentic origin or exact recency of these files.
Neither independent security researchers nor company representatives have officially confirmed the breach at this point. Still, the sudden appearance of such personal details creates immediate panic among millions of regular platform users.
Understanding the Severe Security Risks for Affected Account Holders
The breach of sensitive personal data provides criminals with a chance for cybercrimes. Once criminals get hold of password information such as password hashes and real contact details, they can start their attacks in a matter of minutes.
For instance, criminals can use this information and execute their attack by performing automated credential stuffing on many well-known apps. It is widely known that users usually use the same login passwords for different services, and the breach of just one service can enable attackers to access online banking, online email services, online shopping, etc.
The scale of these threats is significant; a hacker recently claimed to possess a database of alleged Google Gemini users, further highlighting how criminals are targeting large user bases across different platforms
Moreover, the leak of email addresses and phone numbers gives criminals an opportunity to create effective phishing scams. They can create fake messages and emails from trustworthy companies and trick people into clicking on the links in those messages.
Furthermore, bad actors can utilize exact physical addresses and full names to commit identity theft against unsuspecting individuals. Scammers could potentially open fraudulent credit cards or apply for financial loans using the personal identity of the victim.
Beyond financial damage, the leak of social platform data exposes users to severe personal distress. People frequently use community forums like Zigzag to share sensitive thoughts, private opinions, or personal struggles anonymously.
Criminal organizations are capable of easily blackmailing unsuspecting individuals if they associate their actual identities with names and addresses. Cyber extortionists are known to extort a financial payment by threatening to reveal the online activity of a person to their employers, relatives or other close acquaintances.
Besides, it is important to mention that security experts claim that dating and social media leaks can inflict more emotional damage than any business breach.
Practical Steps Users must Take to Secure their Online Accounts
Every individual who has an active registration with the compromised service should implement protective measures without delay. Firstly, users should access their accounts and change their current passwords straight away. Your new password should be long, complicated, and completely different from those of other sites.
In no case should you use the same password in your banking applications for personal email accounts, or social media. The use of different credentials will make sure that a breach at one online destination does not affect other sites.
Second, account holders should commence the use of the multi-factor authentication option if it’s available in the account settings. Multi-factor authentication is a tool that will require an SMS with a temporary verification code from a mobile phone for every subsequent login attempt.
Therefore, even if the hacker decides to purchase the password hashes from the dark web, they won’t be able to get access to your online accounts without your phone. In addition, you should regularly check your bank statements and credit reports.
Lastly, members should exercise extreme caution in relation to unexpected messages coming from unfamiliar sources. When an email tells you that urgent verification of your account is needed, do not click any link in the contents of the email.
Rather, you should reach the official website page by typing the website address yourself. This active and prompt behavior will make it much less likely that you will fall for internet criminals and identity thieves.