The AMZ Review Trader Leak Quietly Exposed 2,105 Plaintext Passwords
HEROIC analysts have logged a breach connected to AMZ Review Trader, a platform that connected Amazon sellers with people willing to review their products, in our breach intelligence records. The exposed dataset is smaller than many of the breaches we track, covering 2,105 accounts, with a recorded leak date of October 25, 2015. What stands out here is not the scale but the fact that every password in this dataset was stored in plaintext, meaning it was never hashed, salted, or protected in any way before it was exposed.
Why the AMZ Review Trader Leak Is Dangerous
Plaintext passwords are the worst-case scenario in any breach. There is no cracking involved, no cryptography to break. If your email and password appear in this dataset, an attacker already has the exact password you typed when you created your account, ready to use immediately on any other site where you might have used the same one. A small breach with plaintext passwords can actually be more dangerous to the individuals involved than a much larger breach where the passwords were properly hashed.
What Was Exposed in the AMZ Review Trader Database
- Email addresses
- Passwords, stored in plaintext with no encryption or hashing
Why a Small Breach Like This Still Matters
It is tempting to dismiss a leak of a little over two thousand accounts as low risk, but the real danger comes from what people do with a password once they have it, not how many other people also had their password exposed. If you reused this password anywhere else, including your email account, banking apps, or work logins, an attacker can move from AMZ Review Trader straight into those accounts. This is exactly how credential stuffing and account takeover attacks begin, and it can escalate quickly into identity theft or financial fraud if the reused password protects something valuable.
How a Plaintext Password Breach Happens
This incident is classified as a database breach, which means an attacker gained direct access to AMZ Review Trader's backend systems and extracted user records in bulk. Storing passwords in plaintext is considered a serious security failure by modern standards, since it means the platform itself never protected user passwords even before the breach occurred. Once a database like this is stolen, it typically gets copied and shared across breach forums and private channels, where the readable passwords make it especially easy for less technical attackers to put the data to immediate use.
Check If You Were Affected by the AMZ Review Trader Breach
If you ever created an account with AMZ Review Trader, or if you tend to reuse passwords across different sites, it is worth checking your exposure directly. HEROIC's free breach scanner checks your email address against a database of more than 400 billion breached records, including this one, and tells you exactly where your information has been exposed. Run a free scan now to find out if this password is still putting your other accounts at risk.
Breach Breakdown
2,105 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds