Credit card numbers flagged in plaintext export
Brazilian delivery giant iFood confirmed that an unauthorized database access in December 2025 exposed the names, ID numbers, and addresses of 1.2 million users; a hacker claimed to have stolen over 43.8 million records, though iFood disputes that figure. Breaches like this frequently end with cardholder data appearing in plaintext exports - CSV dumps and TXT logs copied to local systems (MITRE T1005). Attackers then mine these files for PCI cardholder data to resell or reuse. Proactive DLP scans drives and uploads for credit card number patterns, flags matches in plaintext and CSV files, and triggers quarantine or alerting before sensitive data leaves the organization. The demo uses synthetic card numbers, so it is safe to run in any environment.
Attack Technique
PCI cardholder data
MITRE ATT&CK
T1005 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗