FinanceBRIEF

Pi Wallet Operator Pi Pay Confirms Data Breach, Offers Convenience Store Vouchers Worth Over NT$500 to Affected Users

E
EffectStory 編輯部Editorial Team
Published · Updated
According to CNA and UDN, Pi Pay (拍付國際) confirmed that some members' names, phone numbers and license plate numbers were exposed after a June 2026 hack of an internal file server, though the transaction system and passwords were unaffected. Affected users can claim convenience store e-vouchers worth over NT$500 between July 17 and October 31, 2026.

What is the scope and impact of the Pi Pay data breach?

According to CNA, Pi Pay (拍付國際, operator of Pi Wallet) confirmed that personal data belonging to some of its members had been exposed. The company stated that the leaked data included names, phone numbers, and license plate numbers, while account passwords, transaction records, and credit card numbers were not affected (E1). UDN's report carried an identical company statement, confirming the same categories of exposed data (E7).

Pi Pay further disclosed that the compromised records included member data retained from projects that went live in 2019 and 2022, specifically involving names, phone numbers, and license plate numbers (E5, E9). This indicates the exposure was not limited to recently collected data but also drew from files kept since earlier system launches.

Were users' transaction systems and passwords safe during the breach?

According to CNA, Pi Pay stated that its service app, transaction system, and website were not breached by hackers. The company said that users' account passwords, transaction records, credit card numbers, and points are all stored in a separate database, and that this database was confirmed to be secure (E4). This distinction — between the compromised internal file server and the untouched transaction database — is central to the company's account of the incident.

How did hackers infiltrate Pi Pay's systems?

According to CNA, Pi Pay disclosed that it was attacked by a hacker group in June 2026. The attackers gained access and unlawfully accessed the company's internal employee file server, resulting in the leakage of some daily operational files (E3). UDN's coverage confirmed the same timeline and description of the intrusion, noting the June 2026 attack targeted the internal file server rather than customer-facing systems (E8).

How is Pi Pay compensating affected users?

According to CNA, Pi Pay said it would provide users confirmed to have had their data accessed with convenience store beverage e-vouchers worth a combined total of over NT$500 (E2). UDN reported the same compensation figure, describing it as a package of e-vouchers valued at more than NT$500 (E10).

According to both CNA and UDN, affected users confirmed to have had their data accessed can claim the designated convenience store beverage e-vouchers through a dedicated company web page between July 17 and October 31, 2026 (E6, E10).

Key facts at a glance

ItemDetailSource
Hack timingJune 2026CNA (E3), UDN (E8)
Data exposedNames, phone numbers, license plate numbersCNA (E1), UDN (E7)
Data originMember records from 2019 and 2022 project launchesCNA (E5), UDN (E9)
Data confirmed safePasswords, transaction records, credit card numbersCNA (E1, E4)
Compensation valueOver NT$500 in convenience store e-vouchersCNA (E2), UDN (E10)
Claim periodJuly 17 – October 31, 2026CNA (E6), UDN (E10)

What this means

The evidence points to a breach confined to an internal employee file server rather than the customer-facing transaction system: Pi Pay stated its app, transaction system, and website were untouched, with passwords and card data held in a separate, confirmed-secure database (E4), even as it acknowledged that names, phone numbers, and license plate numbers tied to 2019 and 2022 member records were accessed (E1, E5, E9). The compensation Pi Pay is offering — e-vouchers worth over NT$500, claimable from July 17 through October 31, 2026 — is scoped specifically to users confirmed to have had their data accessed, matching the narrower category of information the company says was exposed (E2, E6, E10).

數據圖表:拍付國際(Pi拍錢包)、拍付國際(Pi拍錢包) 的 年6月 比較,共 2 項數據,來源 2 處。
(來源:cna.com.tw)

📊 Evidence

E
EffectStory 編輯部Editorial Team

Related

RESEARCH

LLM API Pricing vs. Performance: Major Models Compared (July 2026)

As of 22 July 2026, standard API pricing (input/output per 1M tokens) and Artificial Analysis capability scores for major LLMs: OpenAI GPT-5.6 Sol ($5/$30, 59) and Anthropic Claude Opus 4.8 ($5/$25, 56) lead on capability; xAI Grok 4.5 and Claude Sonnet 5 sit in the value band; the DeepSeek V4 family prices output under $1 for high-volume use. Pricing changes often — verify on official pages.

EffectStory 編輯部 ·
BRIEF

US Commerce Department's AI Testing Chief Resigns After Three Months, Adding to Uncertainty in Trump's AI Policy

According to a report by CNA (Central News Agency), the U.S. Commerce Department confirmed that Chris Fall, director of the Center for AI Standards and Innovation (CAISI), resigned after only three months in the role. The department did not disclose a reason, and a UDN report notes the departure marks the latest personnel shift in the Trump administration's AI policy.

EffectStory 編輯部 ·
BRIEF

Starlink Moves Closer to Taiwan as Telecommunications Management Act Amendment Advances, Chunghwa Telecom Signals Partnership Interest

According to Inside.com.tw, Taiwan's Legislative Yuan Transportation Committee has passed a preliminary review of an amendment to the Telecommunications Management Act that would exempt satellite operators from foreign-ownership caps under national-security review. Per CNYES, Chunghwa Telecom (中華電信) chairman Jie Zhicheng said the company would immediately move to bring in Starlink once the law passes, while Digital Affairs Minister Lin Yi-ching noted Starlink has told the government Taiwan's market potential is limited.

EffectStory 編輯部 ·