
PcComponentes, a leading Spanish technology retailer, has denied claims that its systems were breached or that data from 16 million customers was stolen, while confirming that it detected and contained a credential stuffing attack targeting a limited number of user accounts.
The company said it launched an internal investigation after a threat actor using the name “daghetiaw” published claims that a PcComponentes customer database containing 16.3 million records had been stolen. The actor leaked a sample of about 500,000 records and offered the remaining data for sale. PcComponentes stated that its security teams found no evidence of unauthorized access to its databases or internal systems and rejected the claim regarding the scale of affected customers, noting that its number of active accounts is significantly lower than the figure cited.
PcComponentes operates a large e-commerce marketplace in Spain focused on computers, laptops, peripherals, and hardware, attracting an estimated 75 million unique visitors annually. The company emphasized that it does not store customer passwords or financial information within its systems.
While ruling out a system breach, PcComponentes confirmed that its investigation uncovered evidence of a credential stuffing attack, a method in which attackers use previously exposed email address and password combinations from other incidents to attempt logins at scale. The company said this activity led to the compromise of a small number of customer accounts where credentials had been reused.
The data exposed in those compromised accounts may have included first and last names, national identification numbers, physical addresses, IP addresses, email addresses, and phone numbers. Some of the information circulating online also referenced order details, wish lists, and customer support communications handled through Zendesk, a customer service software platform used by many businesses.
Threat intelligence firm Hudson Rock independently analyzed samples shared by the attacker and identified that the email addresses examined were present in existing infostealer malware logs, with some records dating back several years. The analysis indicated that the credentials were likely harvested from infected personal computers rather than from PcComponentes’ infrastructure.
In response, PcComponentes said it has strengthened account security by deploying CAPTCHA protections on login pages, invalidating all active user sessions, and requiring two-factor authentication for all accounts. Customers have been logged out automatically, and access will only be restored after two-factor authentication is enabled.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543