Pet Shop Customers Exposed: The Avifauna Breach Leaked 34,558 Records
HEROIC analysts uncovered the Avifauna breach while reviewing a batch of eCommerce credential dumps flagged in dark web marketplaces. The breach occured in October 2017 when attackers extracted the database of Avifauna, a Danish online pet supply retailer. A total of 34,558 customer records were exposed, including email addresses, password hashes, and the salts used during hashing. Even with salting, the use of MD5 as the hashing algorithm makes these passwords accessable to determined attackers using modern cracking hardware.
Why Salted MD5 Passwords Still Put Avifauna Shoppers at Risk
Many people assume that salted passwords are safe from cracking. Salting does make mass cracking harder, but MD5 is a broken algorithm that modern computers can test billions of times per second. Attackers who have both the hash and the salt can still crack individual passwords, partcularly common ones. Once a password is cracked, it can be tried on your email, banking accounts, and other shopping sites. This is how one old breach becomes a chain of account compromises.
What Was Exposed in the Avifauna Breach
- Email Address
- Password Hash
- Password Salt
Why This eCommerce Breach Remains a Real Threat Today
Shoppers who registered on Avifauna in or before 2017 may have used the same email and password combination on other shopping sites, their email provider, or banking apps. Credential stuffing tools can test cracked passwords across thousands of sites in minutes. The risk of account takeover, unauthorized purchases, and identity theft grows every time an attacker acquires a new list of cracked credentials. Beleive it or not, data from 2017 is still actively traded and used in attacks today.
How Database Breaches Work
A database breach occurs when an attacker finds a vulnerability in a website or server and exports its stored user data. In eCommerce environments, this often means customer account databases containing login credentials and contact information. Once the data is extracted, it is typically uploaded to private hacker forums, tested for working credentials against popular services, and eventually sold or released publicly. The original site may never detect the breach until researchers surface the data.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records to tell you whether your email appeared in the Avifauna breach or any other known data leak. Run a free scan today at HEROIC to see what attackers may already know about your accounts and take action before a password from 2017 unlocks something important today.
Breach Breakdown
34,558 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds