The Audrey Kawasaki Breach Exposed Enough Logins to Fill a Small Town
HEROIC analysts traced a leaked dataset attributed to Audrey Kawasaki, a US-based arts and design site (audkawa.com), back to late August 2018. The dataset, containing 12,618 records, surfaced on a hacking forum and pairs email addresses with SHA1 password hashes. The source has not been independently verified, but the data structure looks like a straightforward database export packaged into a combolist for resale or trading among cybercriminals.
Why This Is Dangerous
SHA1 is an older hashing algorithm, and modern computing power makes it far easier to crack than newer methods like bcrypt. That means many of the passwords in this dataset can likely be recovered by anyone with the right tools. Once cracked, each email and password pair becomes a working set of login credentials that can be tested against other websites, a technique known as credential stuffing. If you signed up at this site and reused that password anywhere else, those other accounts are exposed too.
What Was Exposed
- Email addresses
- Password hashes (SHA1)
Why This Matters
A combolist built from email and password pairs is one of the most useful tools in an attacker's kit. It requires no special skill to use, just automation to test thousands of logins per minute against banking sites, email providers, and shopping accounts. Password reuse is what turns a small breach like this one into a much bigger problem, since a single recovered password can unlock several unrelated accounts belonging to the same person.
How Database and Combolist Leaks Work
This incident is tagged as both a database leak and a combolist. A database leak is the raw export, typically pulled from a compromised or poorly secured backend. A combolist is what criminals make from that raw data afterward: a cleaned up, reformatted file of email and password pairs, stripped of anything unnecessary, built specifically to be fed into automated login tools. Combolists like this one circulate widely on forums and Telegram channels, often changing hands many times after the original leak.
Check If You Are Affected
If you have ever created an account tied to this email address, it is worth checking whether your details are part of this leak. HEROIC's free breach scanner searches a database of more than 400 billion leaked records, including this one, and shows you your exposure in seconds so you can reset any reused passwords before someone else uses them first.
Breach Breakdown
12,618 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds