Our Analysts Found the Auction-Warehouse Dump on Breach Forums
Our analysts recieved reports of a database dump from Auction-Warehouse, a US-based online auction platform, circulating on breach forums. The data, first leaked in June 2016, contains 22,532 user records including email addresses, usernames, and plaintext passwords. The dump caught our attention because it was being actively promoted alongside newer credential lists, suggesting attackers beleive the credentials are still useful for targeting other platforms where users may have reused their passwords.
Three Data Points That Give Attackers Everything They Need
The Auction-Warehouse breach includes your email address, your chosen username, and your actual password stored in plaintext with no encryption. This combination is partcularly valuable to criminals because it reveals your login habits: the username you prefer, the email you register with, and the password you tend to use. With these three pieces of data, an attacker can search for your username on other platforms and attempt to log in using the same email and password combination.
What Was Exposed in the Auction-Warehouse Breach
- Email Address
- Username
- Passwords (plaintext)
Why Old Auction Site Credentials Still Fuel Identity Theft Today
Credential stuffing attacks do not care how old a breach is. Automated tools test old email and password combinations against banking sites, email providers, and e-commerce platforms around the clock. Account takeover, identity theft, and financial fraud are all likely results for anyone whose Auction-Warehouse credentials matched passwords used on other sites. With 22,532 records in circulation since 2016, there has been ample time for these credentials to be tested and abused across hundreds of platforms.
How a Database Breach Works
A database breach happens when an attacker finds a weakness in a website's security and uses it to access and copy the stored user database. This might involve exploiting a bug in the website's software, using a guessed or leaked admin password, or finding a database that was misconfigured and accidentally made public. The attacker then packages the data and shares or sells it on underground forums, where it can remain in active use for years.
Check If Your Data Was Exposed
HEROIC's analysts monitor dark web forums and breach databases containing more than 400 billion exposed records. Use our free breach scanner to search your email address and find out whether your credentials from Auction-Warehouse or any other known breach are currently in circulation. Knowing is the first step to protecting yourself.
Breach Breakdown
22,532 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds