Handout B: DSAR Response Export

Context: This is the data export sent in response to DSAR #178. The email bounced. Review what was exposed.

Field Value
Export Date: 2026-02-06 14:32:17 UTC
Request ID: DSAR-2026-0178
Requester Email: alex.wong.gamer@gmail.com [BOUNCED]
Processed By: Jamie Chen
Verification Status: ID Document Accepted
Response Sent: 2026-02-06 14:35:22 UTC
Delivery Status: FAILED - Address not found

Section 1: Account Information

Field Value
Username: AlexWongPlays
Display Name: Alex W.
Email (Account): alex.wong.real@gmail.com
Account Created: 2023-03-14
Last Login: 2026-02-04 19:22:08 UTC
Account Status: Active
2FA Enabled: No
Linked Accounts: Discord: AlexPlays#4521, Twitch: alexwongttv

Section 2: Personal Information

Field Value
Full Name: Alexander James Wong
Date of Birth: 1994-07-22
Address: 1847 Maple Drive, Apt 4B, San Jose, CA 95126
Phone: +1 (408) 555-0147
Country: United States
State/Region: California
Timezone: America/Los_Angeles

Section 3: Payment Information

Field Value
Payment Method: Credit Card (Visa)
Card Last 4: 4829
Billing Name: Alexander J Wong
Billing Address: Same as personal address
Total Spent: $347.82
Last Purchase: 2026-01-28 β€” Nebula Expansion Pack ($24.99)

Section 4: Purchase History (Last 12 Months)

Date Item Amount Method
2026-01-28 | Nebula Expansion Pack | $24.99 | Visa *4829
2025-12-15 | Holiday Bundle 2025 | $49.99 | Visa *4829
2025-11-03 | Premium Battle Pass S4 | $14.99 | Visa *4829
2025-08-22 | Founders Pack | $79.99 | Visa *4829
2025-06-10 | Character Skin Bundle | $19.99 | Visa *4829

Section 5: Data Storage & Processing Information

THIS SECTION WAS INCLUDED BECAUSE THE DSAR REQUESTED IT

System Details
Account Database: PostgreSQL cluster (accounts-prod-west)
Payment Processing: Stripe integration via payment-api-v2
Gameplay Data: MongoDB (gamedata-prod) + Redis cache
Analytics: Snowflake warehouse (analytics-prod)
Authentication: Auth0 tenant (chimera-prod)
CDN/Assets: CloudFront distribution d2xyz123
Backup Retention: 90 days encrypted, AWS S3 Glacier
Data Centers: us-west-2 (primary), us-east-1 (DR)

IM NOTES: This export reveals multiple attack opportunities:

  • Full PII enables identity theft or targeted phishing
  • Payment partial + billing address enables card fraud
  • Linked accounts enable lateral social engineering
  • Section 5 is a COMPLETE INFRASTRUCTURE MAP for Phase 2 targeting
  • No 2FA means account takeover is trivial if password is weak

The requester (if they exist) has been fully profiled. The attacker knows exactly where to look next.