Breach Intelligence Report 20 Jun 2025

18K Amidon Jewelers Breach: Credentials Still Circulating

HEROIC
HEROIC Threat Intelligence Team
Email Address Password Hash
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 18,579
Source Type Database
Origin Darkweb
Password Type MD5

HEROIC analysts identified the Amidon Jewelers breach as part of a broader sweep of e-commerce credential databases circulating on hacking forums. The breach occurred in August 2018, when attackers compromised the database of Amidon Jewelers, a US-based online jewelry retailer. A total of 18,579 user records were exposed, each containing an email address and an MD5 hashed password. What is notable about this incident is how the data has continued to resurface in compiled credential lists years after the original breach, with attackers specifically targeting e-commerce users who may not have changed their passwords since 2018.


How Stolen Jewelry Store Credentials Fuel E-Commerce Fraud

E-commerce accounts are high-value targets because they are often linked to saved payment methods, shipping addresses, and purchase history. When an attacker cracks an MD5 password hash from the Amidon Jewelers breach and tests it against other shopping platforms, they can make fraudulent purchases using stored payment information, redirect shipments, or harvest personal details for identity theft. The combination of email and crackable password also makes it accessible for attackers to attempt account takeover on email providers, which then allows them to reset passwords on virtually any other service you use.


What Was Exposed in the Amidon Jewelers Breach

  • Email Address
  • Password Hash

Why the Amidon Jewelers Breach Is Still Relevant Years Later

Data from a 2018 breach does not become harmless over time. Attackers continue to compile, update, and sell older databases because users are slow to change passwords. Credential stuffing tools make it trivial to test thousands of email and password combinations automatically across dozens of platforms. If you shopped at Amidon Jewelers before 2018 and have not changed your password, your login credentials may still be valid somewhere and in the hands of someone who should not have them. This creates ongoing risk for account takeover, identity theft, and financial fraud.


How Database Breaches Work

A database breach happens when an attacker identifies and exploits a security flaw in a website, gaining unauthorized access to the system where user records are stored. The attacker extracts the user database, which typically contains email addresses and hashed passwords. When weaker algorithms like MD5 are used for hashing, those passwords can be recovered quickly using precomputed lookup tables or specialized cracking tools. Once recovered, the plain-text credentials are used in automated attacks against other websites and services where the user may have the same login.


Check If Your Data Was Exposed

HEROIC's free breach scanner searches more than 400 billion records from hundreds of known breaches, including e-commerce databases like Amidon Jewelers. If your email address appeared in this breach or any other, you will see a full report instantly. Check your email now at HEROIC's scanner and take action before your old credentials are used against you.

Breach Breakdown

Domain N/A
Leaked Data Email Address, Password Hash
Password Types MD5
Date Leaked 20 Jun 2025
Check in 5 seconds

18,579 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,171 scanned today
Breach Rank #11,774 by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $134.4K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance