1,823,891 Email Addresses Exposed in the 1.8KK Shopping USA Base Leak
HEROIC analysts identified this stealer log on April 2, 2023. The breach exposed 1,823,891 records, with stolen data including email addresses, plaintext passwords, and URLs. The source is identified as 1.8KK Shopping USA Base.
Why This Is Dangerous
This breach targets US-based shopping accounts. With plaintext passwords exposed, attackers can attempt logins on major retail websites, online marketplaces, and e-commerce platforms. Shopping accounts frequently store saved payment cards, home addresses, and purchase histories, making them high-value targets for financial fraud.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs (website addresses where credentials were stolen)
Why This Matters
Nearly 1.8 million shopping account credentials in this breach create significant fraud risk for US consumers. Criminals can use these credentials to make unauthorized purchases, drain loyalty points, access stored payment cards, and sell account access to other bad actors. Password reuse across email and financial accounts compounds the risk considerably.
How Stealer Logs Work
Stealer logs originate from malware installed on victims' computers without their knowledge. The malware monitors browser activity, captures saved passwords, and records login credentials as users shop online. This harvested data is packaged into files and distributed across dark web forums and private channels, giving criminals direct access to working account credentials.
Check If You Are Affected
HEROIC offers a free breach scanner that searches 400 billion records. Search your email address now to see if your credentials appear here or elsewhere. Free, takes seconds.
Breach Breakdown
1,823,891 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds