Threat Actor Claims to Sell Qi Card Iraq Database for $65, Raising Concerns Over Potential Data Exposure

A threat actor is advertising what they claim is a database associated with Qi Card Iraq, one of the major services used for salaries, pensions, and social benefits in Iraq.

The database is reportedly being offered for $65 on a cybercrime forum. As purported evidence, the seller shared a screenshot showing multiple rows of Arabic-language records that appear to contain personal and account-related information.

However, there is currently no independent confirmation that the advertised data came from Qi Card.

Important details remain unknown, including the number of records, database size, date of any alleged breach, and how the information was obtained. The authenticity, freshness, and original source of the data also remain unverified.

The unusually low asking price and limited evidence require caution. The advertised information could potentially be previously leaked data, information collected from the internet, resold data, or fabricated records, rather than evidence of a new compromise.

If the data is genuine, it could potentially be used for identity theft, phishing, fraudulent phone calls, impersonation, or attempts to obtain card information and one-time passwords (OTP).

The Secondary Scam Risk

One of the most important concerns is that criminals could use the news of the alleged breach itself to target customers.

For example, a scammer could call someone claiming to be customer support, mention the alleged data leak to create fear, and then ask for an OTP to “secure” the customer’s account.

Customers should never provide OTPs, PINs, card details, or other sensitive information in response to unsolicited calls or messages.

It is also important to remember that a database being advertised for sale does not automatically mean that a customer’s account or money has been compromised.

Users should avoid suspicious links, verify communications through official channels, and avoid downloading, sharing, or redistributing alleged leaked data.

The incident highlights an important cybersecurity lesson: sometimes the news about a data breach can become the starting point for a new fraud campaign.