FinanceBRIEF

Pi Wallet Operator Pi Pay Confirms Data Breach, Offers Convenience Store Vouchers Worth Over NT$500 to Affected Users

E
EffectStory 編輯部Editorial Team
Published · Updated
According to CNA and UDN, Pi Pay (拍付國際) confirmed that some members' names, phone numbers and license plate numbers were exposed after a June 2026 hack of an internal file server, though the transaction system and passwords were unaffected. Affected users can claim convenience store e-vouchers worth over NT$500 between July 17 and October 31, 2026.

What is the scope and impact of the Pi Pay data breach?

According to CNA, Pi Pay (拍付國際, operator of Pi Wallet) confirmed that personal data belonging to some of its members had been exposed. The company stated that the leaked data included names, phone numbers, and license plate numbers, while account passwords, transaction records, and credit card numbers were not affected 1. UDN's report carried an identical company statement, confirming the same categories of exposed data 7.

Pi Pay further disclosed that the compromised records included member data retained from projects that went live in 2019 and 2022, specifically involving names, phone numbers, and license plate numbers (E5, E9). This indicates the exposure was not limited to recently collected data but also drew from files kept since earlier system launches.

Were users' transaction systems and passwords safe during the breach?

According to CNA, Pi Pay stated that its service app, transaction system, and website were not breached by hackers. The company said that users' account passwords, transaction records, credit card numbers, and points are all stored in a separate database, and that this database was confirmed to be secure 4. This distinction — between the compromised internal file server and the untouched transaction database — is central to the company's account of the incident.

How did hackers infiltrate Pi Pay's systems?

According to CNA, Pi Pay disclosed that it was attacked by a hacker group in June 2026. The attackers gained access and unlawfully accessed the company's internal employee file server, resulting in the leakage of some daily operational files 3. UDN's coverage confirmed the same timeline and description of the intrusion, noting the June 2026 attack targeted the internal file server rather than customer-facing systems 8.

How is Pi Pay compensating affected users?

According to CNA, Pi Pay said it would provide users confirmed to have had their data accessed with convenience store beverage e-vouchers worth a combined total of over NT$500 2. UDN reported the same compensation figure, describing it as a package of e-vouchers valued at more than NT$500 10.

According to both CNA and UDN, affected users confirmed to have had their data accessed can claim the designated convenience store beverage e-vouchers through a dedicated company web page between July 17 and October 31, 2026 (E6, E10).

Key facts at a glance

ItemDetailSource
Hack timingJune 2026CNA 3, UDN 8
Data exposedNames, phone numbers, license plate numbersCNA 1, UDN 7
Data originMember records from 2019 and 2022 project launchesCNA 5, UDN 9
Data confirmed safePasswords, transaction records, credit card numbersCNA (E1, E4)
Compensation valueOver NT$500 in convenience store e-vouchersCNA 2, UDN 10
Claim periodJuly 17 – October 31, 2026CNA 6, UDN 10

What this means

The evidence points to a breach confined to an internal employee file server rather than the customer-facing transaction system: Pi Pay stated its app, transaction system, and website were untouched, with passwords and card data held in a separate, confirmed-secure database 4, even as it acknowledged that names, phone numbers, and license plate numbers tied to 2019 and 2022 member records were accessed (E1, E5, E9). The compensation Pi Pay is offering — e-vouchers worth over NT$500, claimable from July 17 through October 31, 2026 — is scoped specifically to users confirmed to have had their data accessed, matching the narrower category of information the company says was exposed (E2, E6, E10).

數據圖表:拍付國際(Pi拍錢包)、拍付國際(Pi拍錢包) 的 年6月 比較,共 2 項數據,來源 2 處。
(來源:cna.com.tw)

📊 Evidence

FAQ

What is the scope and impact of the Pi Pay data breach?

According to CNA, Pi Pay (拍付國際, operator of Pi Wallet) confirmed that personal data belonging to some of its members had been exposed.

Were users' transaction systems and passwords safe during the breach?

According to CNA, Pi Pay stated that its service app, transaction system, and website were not breached by hackers.

How did hackers infiltrate Pi Pay's systems?

According to CNA, Pi Pay disclosed that it was attacked by a hacker group in June 2026.

How is Pi Pay compensating affected users?

According to CNA, Pi Pay said it would provide users confirmed to have had their data accessed with convenience store beverage e-vouchers worth a combined total…

Related data

E
EffectStory 編輯部Editorial Team

Related

BRIEF

CNA Launches Taiwan's First News MCP Tool, AskCNA, Priced at NT$200 a Month

Central News Agency (中央社) launched CNA MCP on August 31, 2026, Taiwan's first news tool built on Anthropic's Model Context Protocol (released November 2024), letting AI agents such as Claude, ChatGPT, and Grok retrieve and cite its archives in real time. The tool integrates nearly 5 million newswire stories, 3.5 million photos, and open data from about 150 government agencies, priced at NT$200 a month with an early-bird bonus-quota plan, and received funding from Google Taiwan's nDX Digital Innovation Grant Program.

EffectStory 編輯部 ·
BRIEF

Sony Music and Warner Chappell Sue Anthropic Over Alleged 'Brazen Campaign' of Copyright Theft

Sony Music Publishing and Warner Chappell, joined by other music publishers, sued Anthropic and co-founders Dario Amodei and Benjamin Mann in the U.S. District Court for the Northern District of California, alleging illegal torrenting, scraping, and downloading of copyrighted lyrics and sheet music. The publishers seek up to $150,000 per work and $25,000 per instance of stripped copyright data, a total that could reach several billion dollars. The filing follows Anthropic's earlier $1.5 billion settlement in the Bartz case.

EffectStory 編輯部 ·
BRIEF

Why Anthropic Turned to Nscale and Lambda for $45B and $35B GPU Compute Deals

Anthropic has assembled compute capacity across at least four NVIDIA-linked providers: a $35 billion contract with Lambda tied to a Hut 8-built Texas data center, a $45 billion, six-year deal with Nscale for a West Virginia campus running NVIDIA Vera Rubin systems, a $10 billion contract with startup Volta in Norway, and a reported (unconfirmed) tenancy at Riot Platforms' Rockdale, Texas site. NVIDIA sits inside nearly every arrangement — as investor, lessor, or chip supplier.

EffectStory 編輯部 ·