AtendeSaude
We noticed a significant data exposure originating from AtendeSaude, a Brazilian e-commerce platform focused on healthcare equipment. The incident, discovered around June 16, 2022, involved the compromise of their management portal, leading to the exfiltration of a substantial volume of user data. What struck us was the breadth of personally identifiable information (PII) included in the dataset, coupled with the subsequent dissemination of this information on a prominent cybercrime forum, indicating a deliberate effort to monetize the breach. The presence of bcrypt hashed passwords suggests a degree of security awareness, yet the overall exposure still presents considerable risks.
The breach at AtendeSaude appears to have originated from a compromise of their management portal, leading to the exposure of approximately 150,000 records. Of particular concern is the dataset containing 34,812 unique email addresses, alongside full names, phone numbers, gender, and birthdates. The inclusion of bcrypt hashed passwords, while a positive security measure, does not negate the risk of credential stuffing or brute-force attacks if weak passwords were used. The data was subsequently found to be circulating on a well-known cybercrime forum, amplifying the potential for misuse by malicious actors. The source structure of the leak points towards a direct database extraction, rather than a web application vulnerability, suggesting a potential compromise of administrative credentials or direct database access.
While specific news coverage directly detailing this AtendeSaude breach is limited, the nature of the leaked data and its appearance on cybercrime forums align with broader trends observed in the healthcare and e-commerce sectors. Such breaches often fuel phishing campaigns targeting individuals whose data has been exposed, as well as targeted attacks against organizations that may reuse credentials. The presence of PII like birthdates and phone numbers can be leveraged for sophisticated social engineering attacks. Further OSINT investigation into the specific cybercrime forum where the data was shared could provide more granular details on the threat actor's motivations and methodologies.
Breach Breakdown
34,812 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds