eCommerce Customers Exposed: Cheerleading.com Leaked 66K Records
In January 2022, Cheerleading.com, a U.S.-based e-commerce store selling cheerleading apparel and equipment, occured a database breach that exposed the personal records of 66,525 customers. The stolen data was subsequently observed circulating on underground forums, where threat actors verified and traded the credentials for use in account takeover campaigns. For a niche retail platform, the number of affected records is substantial, and the inclusion of real names alongside email and password data makes this breach particularly damaging for victims.
What Attackers Can Do With Cheerleading.com Customer Data
Armed with full names, email addresses, and SHA512 password hashes, attackers can build highly convincing phishing emails that reference the victim by name to recieved a higher click-through rate. Even though SHA512 is stronger than MD5, it is not immune to cracking, especially when passwords are short or common. Cracked credentials are then tested across banking, email, and social media platforms through automated credential stuffing tools, often compromising additional accounts within hours.
What Was Exposed in the Cheerleading.com Breach
- Email Address
- Password Hash (SHA512)
- First Name
- Last Name
Why eCommerce Breaches Put Shoppers at Risk
Online retail customers are seperate targets from enterprise users because they routinely reuse the same email and password combination across dozens of shopping accounts. When a single store is breached, attackers gain a master key that potentially unlocks accounts on Amazon, eBay, PayPal, and other services. The combination of real names and email addresses also enables identity fraud and social engineering, allowing criminals to impersonate the victim or contact them with tailored scams referencing their purchase history.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a website's backend data store, typically by exploiting a software vulnerability such as SQL injection, using compromised administrative credentials, or targeting an exposed server. Once access is obtained, user tables containing account information are exported in bulk. The stolen data is often packaged and sold or shared on hacking forums, where it is used for credential stuffing, phishing, and identity theft. Smaller e-commerce sites like Cheerleading.com are frequent targets because they often lack dedicated security teams and may run outdated software.
Check If Your Data Was Exposed
HEROIC's DarkWatch scans over 400 billion breached records, including data from the Cheerleading.com breach. Visit HEROIC.com to run a free check on your email address and find out if your credentials appeared in this or any other known data breach. If you are affected, update your password immediately and avoid reusing it on any other platform.
Breach Breakdown
66,525 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds