Dark Web Intel: Cable-Trader Breach Put 11,970 UK eCommerce Accounts Online
HEROIC analysts identified the Cable-Trader breach while conducting threat intelligence sweeps of underground forums specializing in UK-origin credential data. The breach dates to August 2018, when a database from the British eCommerce platform was posted on a popular hacking forum. The dataset contained 11,970 unique records, including email addresses and MD5-hashed passwords. Though the record count is relatively modest, the commercial nature of the platform gives these credentials elevated value: users of an eCommerce site are more likely to reuse passwords on payment platforms, retail accounts, and financial services.
What Attackers Can Do With UK eCommerce Login Credentials
An eCommerce customer account holds more value than a typical forum registration. Users on platforms like Cable-Trader may have saved shipping addresses, payment method references, and order histories. Attackers who obtain these credentials test them first against the source platform, then pivot immediately to larger retailers, PayPal, banking apps, and email providers. The email address itself is often the primary target, since gaining access to someone's inbox gives an attacker the ability to reset passwords across every other service that person uses. Credential stuffing attacks against UK-based services are a persistant and growing threat.
What Was Exposed in the Cable-Trader Database
- Email addresses
- MD5 hashed passwords
The dataset contained 11,970 unique email and password hash pairs from Cable-Trader customers. Passwords were stored using the MD5 hashing algorithm, which is considered cryptographically broken by modern standards. MD5 hashes can be reversed quickly using precomputed lookup tables, meaning the practical protection they offer is minimal for most commonly used passwords.
Why This Matters for Credential Stuffing, Account Takeover, and Fraud
The Cable-Trader breach is a textbook example of a smal eCommerce incident that grows into a broader threat over time. The original breach affected a niche platform, but the credentials it exposed feed into the same combolists used to attack major banks, email providers, and retail giants. Every time that combolist gets redistributed, those 11,970 accounts get tested again. Users who have not changed their password since 2018 remain at risk today. Account takeover, identity theft, and financial fraud are all downstream consequences of a credential breach that most victims never knew happened.
How Database and Combolist Breaches Work
The Cable-Trader breach follows a standard database and combolist attack pattern. An attacker gains access to the platform's backend database, extracts the user table, and formats the results into a usable credential file. That file is then shared on hacking forums as a standalone leak or bundled into a larger combolist. Once in a combolist, the data gets tested automatically against hundreds of websites using credential stuffing tools. The MD5 hashing used by Cable-Trader provides some delay, but most simple passwords stored as MD5 hashes are crackable within seconds using publicly available rainbow tables. After cracking, those passwords become fully usable in stuffing attacks with no further obstacls.
Check If Your Cable-Trader Credentials Have Been Exposed
HEROIC's breach intelligence database contains over 400 billion records, including the Cable-Trader dataset and thousands of similar eCommerce breaches. If you shopped or registered on Cable-Trader, or reused that email and password combination on any other platform, your credentials may already be in active circulation. Use the HEROIC free breach scanner to check your exposure in seconds. No account required.
Breach Breakdown
11,970 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds