Chanti Breach Put 92,045 Email and Password Pairs Online in 2018
HEROIC analysts identified the Chanti breach while reviewing historical records that have recieved renewed attention in credential trading communities. In January 2018, the Swedish online jewelry retailer Chanti lost 92,045 user records in a database compromise. The exposed data included email addresses paired with passwords stored in plaintext, meaning anyone who got hold of this data could read every password directly without any cracking required.
Why Plaintext Passwords Put Chanti Users at Immediate Risk
When passwords are stored in plaintext, attackers do not need to do any extra work. They can take the email and password pairs and attempt to log in to other websites straight away. This kind of attack, called credential stuffing, is partcularly dangerous because most people reuse passwords across multiple accounts. A stolen Chanti password could open the door to email accounts, banking apps, or social media profiles.
What Was Exposed in the Chanti Breach
- Email Address
- Plaintext Password
Why a 2018 Jewelry Site Breach Still Matters Today
Old breaches do not expire. The 92,045 Chanti records have been circulating in underground communities for years, and attackers continue to test these credentials against active accounts. If someone used the same password on Chanti that they use on their work email or bank, they may still be accessable to attack right now. Credential stuffing, account takeover, and identity theft are all real outcomes from breaches like this one.
How a Database Breach Works
A database breach happens when an attacker finds a weakness in a website's security and gains access to the database where user information is stored. In many cases the attacker copies the entire database and walks away with thousands or millions of records. The website owner may not notice for weeks or months. Once the data is in criminal hands it gets shared, sold, and used in attacks against other platforms.
Check If Your Data Was Exposed
HEROIC offers a free breach scanner backed by a database of over 400 billion records. You can search your email address right now to find out whether your information appeared in the Chanti breach or any of the thousands of other breaches in our database. Knowing is the first step to protecting yourself.
Breach Breakdown
92,045 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds