One Old Database. 133,761 Accounts. Antonov Clima Breach Still Active.
HEROIC analysts identified the Antonov Clima breach while monitoring underground forums where older credential databases are frequently traded and repackaged. In April 2018, this Bulgarian eCommerce platform specializing in HVAC and household appliances had its database compromised, exposing 133,761 records. The dataset contained email addresses paired with password hashes, and the hashing method used was MD5, an algorithm so outdated and weak that modern computers can crack most of those passwords in a matter of seconds. The recieved data showed a platform that stored sensitive user credentials without adequate protection.
Why MD5 Password Hashes Are a Danger to Antonov Clima Users
MD5 was once used to scramble passwords before storing them, but it has been considered broken for over a decade. Attackers can run a list of common passwords through the same process and compare results until they find a match, a technique called a dictionary attack. They can also use precomputed tables of billions of MD5 hashes to look up cracked passwords almost instantly. This means the 133,761 password hashes in this breach are seperate from being safe in any meaningful way. Once cracked, those passwords can be tested against email services, banking platforms, and any other site the victim uses, giving attackers wide access across multiple accounts with no additional effort.
What Was Exposed in the Antonov Clima Breach
- Email Address
- Password Hash
Why a Bulgarian eCommerce Breach Still Threatens Users Worldwide
It might seem like a regional appliance retailer in Bulgaria would have limited impact, but credential stuffing attacks are global and automated. Cybercriminals do not care where a password was leaked from. They simply load the cracked credentials into tools that test millions of login combinations per day across major platforms. Users who reused their Antonov Clima password on popular services like Amazon, PayPal, or social media accounts are directly at risk of account takeover. Beyond that, having a confirmed email address and password combination allows attackers to craft highly convincing phishing emails that reference real account details, increasing the chance that victims fall for identity theft or financial fraud schemes.
How a Database Breach Works
A database breach occurs when an unauthorized person gains access to the system where a website stores its user data. This can happen through exploiting a software vulnerability, guessing or stealing an administrator password, or finding a server that was accidentally left open to the internet without proper security controls. Once inside, the attacker can download the entire user database in minutes. The stolen file typically contains every user account, including email addresses, password hashes, and any other information the platform collected. In the Antonov Clima case, the weak MD5 hashing meant the passwords offered little real protection once the database was copied.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records to check whether your email address or passwords have surfaced in known data breaches, including incidents like Antonov Clima. Visit HEROIC today to run a free scan and find out whether your credentials are already in the hands of cybercriminals.
Breach Breakdown
133,761 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds