According to an exclusive report from United Daily News (UDN), hacker group Settra claimed to have infiltrated PChome's web and payment systems on June 10, releasing a detailed 12-page "complete penetration report" on the darknet. The report allegedly documents the intrusion steps, access paths, and stolen data. The group says it obtained 102GB of internal data, including 3.5 million user records, employee ID numbers and salaries, numerous resumes, API integration docs, production database schemas, internal audit reports, and anti-money laundering (AML) compliance documents. PChome had not responded at press time, and the details could not be independently verified.
Beyond Personal Data
The UDN report cites cybersecurity analysts saying the attack scope extended beyond PChome's e-commerce platform to its entire payment ecosystem, including PayLink, Pi Wallet, and PayLink services. While Taiwan has seen third-party payment data breaches before, if confirmed, Pi Wallet would be the first third-party payment provider in Taiwan hit by ransomware.
The report notes that if member data, technical documents, compliance records, and 9 years of operational data were all taken simultaneously, the attacker likely accessed more than just one database—piecing together the company's entire operational logic. What was stolen isn't just 3.5 million records, but potentially a map that reveals how the business operates.
Analysts warn that such data can fuel more sophisticated phishing attacks, business email compromise (BEC), supply chain infiltration, or long-term persistent threats. If unauthorized access is confirmed, the impact could extend beyond PChome to partner banks and the broader fintech ecosystem.
Settra's Report-Based Extortion
Settra is a ransomware group that emerged in 2026, employing a double extortion strategy—encrypting systems while stealing data, then threatening to leak it. Unlike traditional groups, Settra tends to "document" the attack process, releasing reports that detail intrusion methods and data inventories. The UDN report notes this approach amplifies pressure on victims and shifts the incident from a data breach to a governance crisis. By weaponizing transparency, Settra turns corporate disclosure against the target.
Zheng Jiahai, general manager of Junmeng Technology, told UDN that firms need real-time anomaly detection, least-privilege access, data classification, network segmentation, and zero-trust architecture to limit lateral movement. He also pointed to deception technology as a growing trend, with security focus shifting from "whether breached" to "whether data visibility and controllability are maintained."
PChome's parent company issued a statement saying Pi Wallet operates as an independent third-party payment service, and its security and system management mechanisms are being reviewed by the operations team. The company said it needs further clarification and declined to comment on unverified information.

