Dark-web card data, 98 Bunnings items, and one PowerPass account: how a South Australian man was caught
Aijaypal Tim Sanghera used stolen credit card numbers, almost certainly bought on the dark web, to order $15,899 worth of goods from Bunnings stores across South Australia. A loyalty account tied every transaction to his name.

Key points
- Aijaypal Tim Sanghera, 38, pleaded guilty to 12 counts of dishonest dealing with property at Berri Magistrates Court in South Australia.
- He placed 11 click-and-collect orders across three Bunnings stores over five weeks in April and May 2026, totalling $15,899.65.
- Police believe he bought a bulk set of stolen credit card numbers from the dark web, an anonymous part of the internet not accessible through normal browsers.
- Twenty of the 98 items ordered were $500 Bunnings gift cards, all linked to Sanghera's own Bunnings PowerPass trade loyalty account.
- Sanghera was sentenced to four months in prison and a two-month good behaviour bond.
Some crimes are elaborate. This one was almost mundane, which is exactly what makes it worth understanding.
Over five weeks in April and May 2026, Sanghera placed 11 click-and-collect orders at Bunnings stores in Berri, Parafield Gardens and Edwardstown in South Australia. He paid for them with stolen credit card numbers. Police prosecutors, as reported by ABC News Australia, told the court those numbers were "likely" purchased as a bulk dataset from the dark web, a collection of hidden websites where stolen financial data is routinely bought and sold for small sums.
How did he get caught?
He used his own loyalty account. Twenty of the 98 items he ordered were $500 Bunnings gift cards, and every one of those cards was registered to his Bunnings PowerPass account, a trade membership scheme that tracks purchases. That single link gave investigators a clear thread to pull.
Police searched Sanghera's home in Bookpurnong on 10 June 2026 and found some of the purchased goods still on the premises. They also found less than a gram of methamphetamine, three ice pipes and a dagger.
| Detail | Figure |
|---|---|
| Total fraudulent spend | $15,899.65 |
| Items ordered | 98 |
| Gift cards purchased | 20 x $500 |
| Goods recovered at address | Value reducing loss to $14,592 |
| Prison sentence | 4 months |
| Good behaviour bond | 2 months |
The credit card companies reversed the charges for the people whose card details were used, so those individuals did not end up out of pocket. Bunnings absorbed the unrecovered loss of $14,592.
Should ordinary people worry about their card details?
Yes, but calmly. This case is a reminder that stolen card numbers circulate on the dark web long after the original breach that exposed them. You may never know your details were taken until a fraudulent charge appears.
Check your bank and card statements regularly, ideally weekly. If your card issuer offers instant transaction alerts by text or app notification, turn them on. Report anything unfamiliar immediately; banks are generally required to reverse fraudulent charges, as happened here.
Magistrate Jay Pandya described Sanghera's offending as "deliberate and relentless" and driven by the need to fund drug use. She accepted his guilty plea and noted genuine remorse, but said community protection had to come first. Sanghera's defence lawyer pointed out that prison does not treat addiction, which is true, and which the court acknowledged in the relatively short sentence handed down.
The deeper lesson here is not about Bunnings or even about dark-web markets. It is about how a loyalty account, designed to reward customers, became the thing that made a fraud trail trivially easy to follow. Convenience and accountability run in both directions.



