t2tea.com
Apr 1, 2024
In April 2024, T2 Tea (t2tea.com), an Australian specialty tea retailer, suffered a data breach affecting approximately 94,739 customer records including over 85,891 unique email addresses. The compromised data includes names, email addresses, dates of birth, genders, phone numbers, physical addresses, scrypt-hashed passwords, partial credit card data (masked card numbers and card types), payment methods, order history, and website activity. The data files reference April 2021 exports from a Salesforce Commerce Cloud (Demandware) platform. The breach was attributed to threat actor 'doubl' and leaked by '@emo' on BreachForums.
Data found in this dataset
Source files
Expand any file to inspect its column headers and the LLM's field-mapping reasoning, recorded during ingestion.
T2tea__Info.txt37 rows
File structure
Notes: Pre-LLM auto-detection: free-form text with visible emails / phones
T2tea__data__MARCUS_Test_directory__T115AI132__custom-attribute.csv0 rows
File structure
Format: CSV·Delimiter: comma·Has header: yes·Quote: "
Notes: NOT DATA — This file is a product attribute/metadata schema definition for T2 Tea's Salesforce Commerce Cloud platform, not a customer record export. It contains only product configuration fields (brewingDegrees, brewingTime, size, googleProductType, etc.) and localization metadata (xml:lang, x-default). No PII columns are present. This appears to be a product catalog schema or configuration file, not a customer data breach export.
T2tea__data__MARCUS_Test_directory__T2-Prod-AU-AUD-Pricebook-030920211223-ist__price-table.csv0 rows
File structure
Format: CSV·Delimiter: comma·Has header: yes·Quote: "
Notes: This file contains product catalog data (product IDs, prices, and availability dates). It does NOT contain customer PII records. All columns are non-PII: product-id (product identifier), amount (price), online-from and online-to (promotional/availability timestamps). This appears to be a product inventory or pricing file, not a customer data export from the breach.
T2tea__data__MARCUS_Test_directory__T2-Prod-GB-GBP-Pricebook-030920211224-ist__price-table.csv0 rows
File structure
Format: CSV·Delimiter: comma·Has header: yes·Quote: "
Notes: This is a product catalog file (product-id, amount, online-from, online-to) containing no PII. All columns are non-PII: product identifiers, pricing, and timestamp ranges. Despite the breach context mentioning customer records, this specific file contains only product/inventory data with no personal information.
T2tea__data__MARCUS_Test_directory__T2-Prod-NZ-NZD-Pricebook-030920211225-ist__price-table.csv0 rows
File structure
Format: CSV·Delimiter: comma·Has header: yes·Quote: "
Notes: This file contains only product catalog data (product IDs, amounts, and date ranges). No PII fields are present. All columns are non-PII: product-id (skip), amount (skip — financial), online-from (skip — timestamp), online-to (skip — timestamp).
T2tea__data__MARCUS_Test_directory__T2-Prod-SG-SGD-Pricebook-030920211226-ist__price-table.csv0 rows
File structure
Format: CSV·Delimiter: comma·Has header: yes·Quote: "
Notes: This file contains only product catalog data (product IDs and prices). No PII fields are present. This is NOT a customer/user record file despite being from the T2 Tea breach context. The breach included customer records, but this particular file appears to be product inventory or pricing data with no personal information.
T2tea__data__MARCUS_Test_directory__T2-Prod-US-USD-Pricebook-030920211227-ist__price-table.csv0 rows
File structure
Notes: This file contains product catalog data (product IDs, prices, online availability dates), not customer PII. It is structured data but contains no personally identifiable information whatsoever. This appears to be a product master file from T2 Tea's inventory system, not a customer record export from the breach.
T2tea__data__MARCUS_Test_directory__T2-Prod-master-catalogue-030920211056-ist__custom-attribute.csv0 rows
File structure
Notes: File contains product catalog metadata (attributes, ratings, ingredients, dimensions) from a Salesforce Commerce Cloud system. No customer PII records present. This is a product catalog export, not a customer data file.
T2tea__data__MARCUS_Test_directory__T2-customer-import-instance-20210311065118422-0.log.csv0 rows
File structure
Notes: The provided data is NOT a JSON array of records as described. Instead, it is a Salesforce Commerce Cloud (Demandware) import log file containing DEBUG and WARN messages from a data import process dated 2021-03-11. The log documents the import of customer data from an XML file (T2_CustomerList.xml) with warnings about undefined/missing attributes. No actual customer records with PII fields are present in this sample. To properly analyze the T2 Tea breach data, the actual JSON array of customer records (containing fields like email, phone, dob, firstName, lastName, address, etc.) would need to be provided. This appears to be metadata/process logs rather than the actual data export.
T2tea__data__MARCUS_Test_directory__customer-full-import-instance-20210401.log.csv0 rows
File structure
Notes: The provided data does not contain actual JSON records. The input consists entirely of debug/warning log messages from a Salesforce Commerce Cloud (Demandware) import process dated 2021-04-01, showing import validation and data warnings. No JSON objects with PII fields are present in the first 50 records as provided. To complete this analysis, the actual T2_CustomerList.xml or exported JSON records from the breach are needed. Based on the breach context (t2tea-2024), expected fields would likely include: email, firstName, lastName, dob, gender, phone, address1, address2, city, state, zip, country, password (scrypt-hashed), and possibly partial credit card data—but these cannot be mapped without seeing the actual structured data records.
T2tea__data__MARCUS_Test_directory__gift-card-products-04072021__custom-attribute.csv0 rows
T2tea__data__MARCUS_Test_directory__t2-sku-import-04082021__custom-attribute.csv0 rows
File structure
Notes: This is NOT DATA — the file is a product catalog metadata export (Salesforce Commerce Cloud / Demandware attribute definitions) with repeated product attribute records (bvAverageRating, bvReviewCount, color, googleProductType, materialAndCare, etc.). No customer PII is present. This is structural/configurational data about product attributes, not customer records. The breach context mentions customer records exist elsewhere in the t2tea-2024 breach, but this particular file contains no PII columns to map.
T2tea__data__MARCUS_Test_directory__teamaker-skus-03312021__custom-attribute.csv0 rows
File structure
Notes: This file is a product catalog metadata export (Salesforce Commerce Cloud / Demandware format) containing only product attributes, ratings, and localization settings. No customer PII records are present. This is NOT a customer data file despite the breach context mentioning customer records—this appears to be a product catalog file from the same system.
T2tea__data__Ricky__customerimport27042021-2__customer.csv2 columns319 rows
File structure
Format: CSV·Delimiter: comma·Has header: yes·Quote: "
| Source column | Mapped field | Confidence | LLM assessment |
|---|---|---|---|
| 1 | high | [1] header 'login', values are valid email addresses with @ symbols | |
| 2 | password | high | [2] header 'password', values are plaintext passwords (rj123lb###) |
Notes: CSV from T2 Tea breach (t2tea-2024). 4 columns total; 2 contain PII (email/password). Column [0] 'customer-no' is internal ID (skipped). Column [3] 'custom-attribute' contains ISO 8601 timestamps (skipped).
T2tea__data__custexport270421.csv13,831 rows
File structure
Notes: Pre-LLM auto-detection: free-form text with visible emails / phones
T2tea__data__customerexport27042021-2.csv14,403 rows
File structure
Notes: Pre-LLM auto-detection: free-form text with visible emails / phones
T2tea__data__customerexport27042021.csv80,348 rows
File structure
Notes: Pre-LLM auto-detection: free-form text with visible emails / phones
T2tea__data__t2-customer-delta-042720212000-ist.csv14,404 rows
File structure
Notes: Pre-LLM auto-detection: free-form text with visible emails / phones