Breach Intelligence Report 20 Jun 2025

One Old Database. 133,761 Accounts. Antonov Clima Breach Still Active.

HEROIC
HEROIC Threat Intelligence Team
Email Address Password Hash
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 133,761
Source Type Database
Origin Darkweb
Password Type MD5

HEROIC analysts identified the Antonov Clima breach while monitoring underground forums where older credential databases are frequently traded and repackaged. In April 2018, this Bulgarian eCommerce platform specializing in HVAC and household appliances had its database compromised, exposing 133,761 records. The dataset contained email addresses paired with password hashes, and the hashing method used was MD5, an algorithm so outdated and weak that modern computers can crack most of those passwords in a matter of seconds. The recieved data showed a platform that stored sensitive user credentials without adequate protection.


Why MD5 Password Hashes Are a Danger to Antonov Clima Users

MD5 was once used to scramble passwords before storing them, but it has been considered broken for over a decade. Attackers can run a list of common passwords through the same process and compare results until they find a match, a technique called a dictionary attack. They can also use precomputed tables of billions of MD5 hashes to look up cracked passwords almost instantly. This means the 133,761 password hashes in this breach are seperate from being safe in any meaningful way. Once cracked, those passwords can be tested against email services, banking platforms, and any other site the victim uses, giving attackers wide access across multiple accounts with no additional effort.


What Was Exposed in the Antonov Clima Breach

  • Email Address
  • Password Hash

Why a Bulgarian eCommerce Breach Still Threatens Users Worldwide

It might seem like a regional appliance retailer in Bulgaria would have limited impact, but credential stuffing attacks are global and automated. Cybercriminals do not care where a password was leaked from. They simply load the cracked credentials into tools that test millions of login combinations per day across major platforms. Users who reused their Antonov Clima password on popular services like Amazon, PayPal, or social media accounts are directly at risk of account takeover. Beyond that, having a confirmed email address and password combination allows attackers to craft highly convincing phishing emails that reference real account details, increasing the chance that victims fall for identity theft or financial fraud schemes.


How a Database Breach Works

A database breach occurs when an unauthorized person gains access to the system where a website stores its user data. This can happen through exploiting a software vulnerability, guessing or stealing an administrator password, or finding a server that was accidentally left open to the internet without proper security controls. Once inside, the attacker can download the entire user database in minutes. The stolen file typically contains every user account, including email addresses, password hashes, and any other information the platform collected. In the Antonov Clima case, the weak MD5 hashing meant the passwords offered little real protection once the database was copied.


Check If Your Data Was Exposed

HEROIC's free breach scanner searches more than 400 billion records to check whether your email address or passwords have surfaced in known data breaches, including incidents like Antonov Clima. Visit HEROIC today to run a free scan and find out whether your credentials are already in the hands of cybercriminals.

Breach Breakdown

Domain N/A
Leaked Data Email Address, Password Hash
Password Types MD5
Date Leaked 20 Jun 2025
Check in 5 seconds

133,761 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,227 scanned today
Breach Rank #3,811 by affected users
Impact Score
5
sensitivity + scale + recency
Est. Financial Impact $967.9K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance