64,691 Plaintext Passwords Dumped From Shopping Accounts
HEROIC uncovered a stealer log dataset labeled 64k Shopping Base on Telegram in February 2023. This collection targets online shopping accounts specifically, containing 64,691 records stolen by infostealer malware. Each record includes an email address, a plaintext password, and the URL of the e-commerce platform the victim was using when their credentials were captured.
Why Plaintext Shopping Passwords Are Especially Dangerous
Shopping accounts often store payment methods, billing addresses, and order histories. With 64,691 plaintext passwords available in this dump, attackers can access these accounts without any decryption or cracking effort. Once inside a shopping account, they can make unauthorized purchases, steal stored payment card details, redirect shipments, or harvest personal information for identity theft schemes.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (e-commerce and online shopping platforms)
Shopping Credentials Fuel Widespread Account Takeover
Credential stuffing attacks are particularly effective with shopping credentials because people often use the same login details across multiple retail sites. Attackers take the email-password pairs from this 64,691-record dataset and test them against major retailers, marketplaces, and payment services. A compromised Amazon password that also works on PayPal and eBay gives attackers access to stored credit cards, linked bank accounts, and purchase capabilities across all three platforms.
How Shopping Credentials End Up in Stealer Logs
Infostealer malware infiltrates devices through fake browser extensions, pirated software, or deceptive advertisements. Once installed, it harvests every password saved in the browser, including all online shopping accounts. The malware also captures cookies that can maintain active sessions, allowing attackers to bypass two-factor authentication in some cases. These stolen credentials are compiled into stealer logs organized by service type, with shopping credentials being among the most commercially valuable on underground markets.
Check If Your Credentials Were Exposed
If you shop online and save passwords in your browser, your e-commerce account credentials could be included in this 64,691-record dump. HEROIC's breach scanner searches more than 400 billion compromised records to identify exposed credentials. Check your email address now to see if your shopping passwords have been leaked, and update them immediately across all retail platforms where you use the same login.
Breach Breakdown
64,691 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds