Neigbuy
Incident posture
Timeline
Summary
Neigbuy, a group‑buying platform majority‑owned by TVB, disclosed that a suspected cyberattack led to unauthorized access of personal data belonging to approximately 33,054 customers, including names, addresses, email addresses, phone numbers and order histories. The Office of the Privacy Commissioner for Personal Data confirmed receipt of a breach notification and launched a formal investigation, while police reported six incidents of individuals impersonating staff to conduct scams. Signs of the intrusion were identified before the notification was made public.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On August 24, 2026, signs of a suspected cyberattack involving unauthorised data access were first detected on the Neigbuy platform. The platform, founded in 2018 and majority‑owned by television broadcaster TVB, provides limited‑time deals on groceries, fresh produce, household goods and other products. Following the detection, Neigbuy submitted a data breach notification to the Office of the Privacy Commissioner for Personal Data on Sunday, August 30, 2026. The Office confirmed receipt of the notification on Tuesday, September 1, 2026, and announced the initiation of a formal investigation into the incident.
The security incident affected 33,054 customers of Neigbuy. Potentially compromised personal information included customers’ names, physical addresses, email addresses, telephone numbers and their online shopping order histories. No further details about the specific systems accessed or the methods used by the attackers were disclosed in the available source. The breach notification triggered the privacy watchdog’s statutory oversight process.
In parallel with the privacy commissioner’s inquiry, law enforcement reported receiving six separate cases in which individuals posed as Neigbuy staff to conduct scams. These scam reports were linked to the breach by authorities, who noted the timing coincided with the disclosed compromise of customer contact details. The Office of the Privacy Commissioner continued its investigation, assessing compliance with data protection obligations and considering any necessary enforcement actions. Neigbuy’s internal response, beyond the breach notification, was not detailed in the source material.
Sources
Sources available to members: 1 source.