ABC Stitch Therapy Data Breach: 14,905 US Craft Accounts Exposed in 2018
Cross Stitch Credentials Exposed: The ABC Stitch Therapy Breach
ABC Stitch Therapy was a US-based e-commerce platform specialzed in cross stitch and needle arts supplies -- the kind of hobbyests community that tends to maintain long-standing accounts with consistent contact information. In August 2018, approximately 14,905 user accounts were exposed in a database breach with a mixed MD5 and bcrypt hash scheme, and the data was subsequently shared on underground forums and incorporated into combolist circulation. The authentecity of this data has made it a persistent combolist entry across multiple credential trading operations.
ABC Stitch Therapy (August 2018): Breach Summary
- Records Exposed: 14,905
- Data Types: Email addresses, password hashes
- Breach Type: Database breach / Combolist
- Password Hash Type: Mixed MD5 and bcrypt -- inconsistent security across accounts
- Country Affected: United States
- Date Leaked: August 24, 2018
Mixed Hash Types: Two Tiers of Risk in One Dataset
The presence of both MD5 and bcrypt hashes in the ABC Stitch Therapy dataset creates a two-speed risk scenario. MD5-hashed accounts are highly vulnerable -- common passwords recoverable in seconds using rainbow table lookups, and more complex passwords crackable within hours using GPU-accelerated tools. Bcrypt accounts enjoy substantially stronger protection: bcrypt's deliberate computational cost makes brute-force attacks orders of magnitude slower.
Which accounts received which hash treatment is not externally documented, but the likely explanation mirrors other mixed-hash datasets: a CMS or platform migration that applied bcrypt to new accounts while legacy accounts retained their original MD5 hashes. Older, longer-standing customers -- likely the most engaged hobbyist community members -- may be among those with MD5-protected credentials.
Niche Hobbyist Communities and Credential Longevity
Cross stitch and needle arts enthusiasts tend to be deeply engaged, long-term community members. An account registered on ABC Stitch Therapy years before 2018 and still active at the time of the breach represents years of credential stability -- the same email address and very possibly the same password used across multiple platforms over that period. Hobbyist e-commerce accounts often go unmonitored from a security perspective; users check in for purchases but rarely audit their account security settings.
This makes the dataset particularly valuable for credential stuffing: consistent, long-standing email addresses with passwords that may not have been rotated in years.
Combolist Persistence: Why 2018 Data Still Circulates
The ABC Stitch Therapy breach data entered combolist circulation shortly after the August 2018 leak and has been identified in multiple subsequent credential trading operations. Combolists aggregating data from multiple 2018-era breaches remain active tools for credential stuffing campaigns targeting e-commerce and streaming platforms. The age of the data does not reduce its utility -- it reduces it only for accounts where passwords have been changed, which many users have not done.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records to determine whether your email address appears in known data breaches, including the ABC Stitch Therapy combolist. Run a free scan at HEROIC.com to check your exposure status.
Breach Breakdown
14,905 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds