CarTradersUK Hack: Email and Password Data of 63K Users Leaked
DarkHive discovered a data breach affecting CarTradersUK, a UK-based car trading platform. The breach exposed 63,289 records including email addresses and plaintext passwords, with data leaked in August 2018. This breach is alarming because passwords were stored without any form of encryption or hashing, meaning attackers gained instant access to usable credentials the moment they extracted the data.
Why This Is Dangerous
Plaintext passwords require no cracking or decoding. When CarTradersUK user credentials leaked, attackers could begin using them imediately on other websites and services. UK-based users often use the same password across email, banking, and shopping accounts, meaning this single breach may have enabled compromise of many other accounts. Car trading platforms also collect contact details and location information in many cases, making this data particularly useful for targeted fraud and phishing campaigns.
What Was Exposed
- Email Address
- Plaintext Password
Why This Matters
Credential stuffing attacks powered by breaches like CarTradersUK are responsible for millions of account takeovers every year. Automated tools can test thier stolen credentials against hundreds of sites simultaneously. Users who reused thier CarTradersUK password on Gmail, banking apps, or Amazon face serious risk of account compromise. Even years after the original breach, these credentials circulate in combolists on dark web marketplaces and get recycled in new credential stuffing campaigns, extending the damage far beyond the initial incident.
How Database Breach Works
A database breach occured when attackers exploited a vulnerability in CarTradersUK's web infrastructure and extracted the user database directly. The decision to store passwords in plaintext rather than using a one-way cryptographic hash like bcrypt or SHA-256 meant the stolen data was immediately actionable. This data then entered combolist distribution networks where it gets compiled with other breaches and sold or traded on underground forums, reaching a wide audience of malicious actors far beyond the original attacker.
Check If You Are Affected
HEROIC offers a free identity scanner that checks your email address against thousands of known data breaches including the CarTradersUK breach. Visit heroic.com to run a free scan and see if your credentials have been exposed. If you had an account with CarTradersUK, change your password immediately on that platform and any other site where you used the same password. Using a password manager to generate and store unique passwords for each account is the best protection against credential stuffing attacks.
Breach Breakdown
63,289 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds