Website that lets you send poop through the post gets hacked


A known threat actor has hacked his way into notorious revenge website ShitExpress and leaked the company’s secure data, including customer email addresses and the messages they sent through the platform.
ShitExpress is an online service that allows people to send actual faeces, through the post, to whomever they desire. It’s designed to be a prank site, where people can purchase a piece of animal faeces and have it delivered to someone’s door, in a box, together with a personalized message.
You can imagine the type of messages someone would send together with a piece of animal dung to their cheating former partners, horrible ex boss, or noisy neighbor – hence why this leak might be troubling to many customers.
SQL Injection flaw
As reported by BleepingComputer, a user going by the name “pompompurin” visited the site in order to send a box to his long-time arch-nemesis, cybersecurity researcher, Vinny Troia. The two go way back, pranking and harassing each other for quite some time, the publication reported.
Upon opening the site, he realized that it was vulnerable to SQL Injection, and soon Mr pompompurin was soon sifting through email addresses, customer messages, and other private data (opens in new tab) associated with the orders.
A day after successfully compromising the site, he leaked the database on a hacking forum. Speaking to the publication about it, pompompurin said the database was surprisingly small: “It’s honestly not that big… There’s about 29,000 orders in the data,” he said.
He also said that he didn’t do it for ransom or anything similar. “I gained access a day before I leaked it, and I notified the website owner after dumping the data. [I’m] not sure if they’ve acknowledged or anything as of yet,” he confirmed.
In response to the incident, ShitExpress acknowledged the breach, and took responsibility, saying: “It’s purely our fault — a human error that could happen to anyone. It was found by one of our customers. We fixed the error immediately.”
As this is a prank site, that gathers almost no customer data at all, there was nothing particular to leak from the compromised endpoints (opens in new tab). Payment data was left with the payment provider, meaning pompompurin never got it.
Via: BleepingComputer (opens in new tab)
Audio player loading… A known threat actor has hacked his way into notorious revenge website ShitExpress and leaked the company’s secure data, including customer email addresses and the messages they sent through the platform. ShitExpress is an online service that allows people to send actual faeces, through the post, to…
Recent Posts
- This is the weirdest looking AI MAX+ 395 Mini PC that I’ve ever seen — and you can apparently hold it comfortably in the palm of your hand
- The Columbia hack is a much bigger deal than Mamdani’s college application
- One of My Favorite Gaming Laptops Gets a Serious Prime Day Cut
- Amazon’s best Kindles are cheaper than ever during Prime Day
- AMD is surpassing Nvidia in one particular market, and I don’t understand why — 11th eGPU based on AMD Radeon RX 7000 series debuts and even has Thunderbolt 5
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022