The Beerman Dump: 15,975 Stolen Login Credentials Hit the Dark Web
HEROIC analysts identified a dataset from Beerman, a Russian restaurant chain based in Novosibirsk that operates beer restaurants, grills, bars, and pizza venues, circulating on a Telegram channel on December 18, 2024. The leaked database exposed 15,975 customer records, including email addresses, SHA1 password hashes, first and last names, and phone numbers.
Why This Is Dangerous
With a customer's email address, name, and phone number in hand, an attacker already has enough to run a convincing phishing or impersonation campaign. Add a password hash to the mix, and the risk grows: SHA1 is an older hashing algorithm that can be cracked with widely available tools, especially against weak or common passwords. Anyone who reused their Beerman password on another account is at risk of that account being taken over too.
What Was Exposed
- Email addresses
- SHA1 password hashes
- First names
- Last names
- Phone numbers
Why This Matters
This combination of data is exactly what fuels credential stuffing attacks, where criminals take leaked email and password pairs and try them against banking, email, and social media logins. Paired with a real name and phone number, the same data also supports SIM-swap attempts, targeted phishing texts, and identity theft. Even a breach of a restaurant chain's customer database can become a stepping stone to much larger fraud if the exposed passwords are reused elsewhere.
How Database Breaches Like This Happen
This incident is classified as a database breach, meaning attackers gained direct access to Beerman's stored customer records rather than harvesting them one at a time. This typically happens through a compromised database server, exposed backup file, or stolen credentials with administrative access. Once inside, an attacker can copy the entire table of user records in one action, which is why database breaches tend to expose large volumes of consistent, structured data like the fields seen here.
Check If You Are Affected
If you have ever created an account with Beerman or reused a password across multiple sites, it is worth checking whether your information appears in this or other leaks. HEROIC's free breach scanner searches a database of more than 400 billion leaked records to show you where your data has surfaced, so you can change exposed passwords before someone else uses them first.
Breach Breakdown
15,975 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds