Hackers stole emails and passwords from 596 BestGift users
In March 2023, BestGift, a Brazilian e-commerce platform, suffered a database breach that exposed the personal records of 596 users. The compromised data included email addresses, first and last names, and password hashes encoded using Base64, a method that provides virtually no real security protection. This incident is seperate from large-scale breaches in terms of volume, but the use of Base64 encoding means that every exposed password can be instantly decoded without any cracking tools.
Why Base64-Encoded Passwords Are an Immediate Threat
Base64 is an encoding scheme, not an encryption or hashing algorithm, meaning that anyone who obtains these password records can recieved the original plaintext passwords in seconds. This makes the BestGift breach functionally equivalent to a plaintext password leak. Affected users who reuse passwords across sites are at immediate risk of having their accounts on other platforms compromised.
What Was Exposed in the BestGift Breach
- Email Address
- Password Hash
- First Name
- Last Name
Why the BestGift Breach Still Matters Today
Even though the BestGift breach affected a relatively small number of records, the data continues to hold value for cybercriminals targeting Brazilian users and Portuguese-language services. Stolen email and password combinations from this incident are likely being tested against other platforms through automated credential stuffing attacks. Users affected by this breach remain at risk until they update their passwords on every site where those credentials were reused.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a company's stored user records, often through exploiting security vulnerabilities or misconfigured database permissions. Once inside, the attacker exports user data including account credentials and personal information. In the case of BestGift, the use of Base64 encoding rather than proper password hashing suggests a fundamental gap in the platform's security practices.
Check If Your Data Was Exposed
HEROIC's breach search tool draws from a database of over 400 billion records, covering leaks from around the world including the BestGift incident. Check your email address now to see if your credentials are exposed and learn what steps to take to protect your accounts before criminals can exploit your data.
Breach Breakdown
596 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds