Nearly 30,000 Black Package Store Customers Had Their Credentials Leaked to the Dark Web.
HEROIC's dark web sensors detected a database leak attributed to Black Package Store, an American online marketplace for alcoholic beverages. Discovered on December 18, 2024, the Black Package Store dump exposed 29,034 records containing first names, last names, email addresses, IP addresses, and bcrypt password hashes. The file was posted on a well-trafficked dark web forum, making the data readily available to credential-stuffing operators and phishing crews.
Why This Black Package Store Database Breach Is Dangerous
Bcrypt is stronger than MD5, but it is not bulletproof. Any weak, short, or reused password in this dataset can still be cracked offline with GPU farms or targeted dictionaries, then used to log into victims' primary email, banking, or shopping accounts. The combination of verified purchase emails, real names, and IP addresses also gives attackers everything they need to craft convincing shipping and delivery phishing scams against a large US customer base.
What Was Exposed in Black Package Store
- Email addresses
- First names
- Last names
- IP addresses
- Bcrypt password hashes
Why This Matters
Alcohol retailers collect age-verified, address-linked buyer profiles, and those profiles remain useful to fraudsters years after the original transaction. Leaked IP addresses help attackers bypass geolocation checks on other services, while the email-name pairs power account takeover attempts across banks, delivery apps, and loyalty programs. A single successful credential match cascades into a multi-service identity compromise.
How Database Breaches Work
E-commerce database breaches typically start with a vulnerable plugin, an exposed admin panel, or credential theft from a third-party integration. Attackers pivot into the production database and export users and orders tables in bulk. The data is then priced and listed on forums like those monitored by HEROIC, where competing operators purchase access to run stuffing attacks, phishing campaigns, or resale bundles.
Check If You Are Affected
HEROIC monitors more than 400 billion compromised credentials from data breaches and dark web leaks. Run a free scan to see if your email or password is part of the Black Package Store breach, and get step-by-step remediation guidance in seconds.
Breach Breakdown
29,034 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds