Dark Web Intel: 16,730 Plaintext Credentials From the Combook Database Dump
HEROIC analysts identified the Combook breach while scanning dark web forums for newly surfaced credential dumps in early 2021. The breach exposed 16,730 user records from Combook, a Russian online bookstore based in the Russian Federation. What makes this breach partcularly alarming is that passwords were stored and leaked in plaintext, meaning anyone who recieved this data had immediate, ready-to-use access to real account credentials without any cracking required.
Plaintext Passwords: The Most Dangerous Kind of Credential Leak
Unlike hashed passwords that require cracking before use, plaintext passwords work immediately. Attackers who accessed the Combook dump could directly attempt logins on Gmail, banking apps, social media, and corporate accounts. Because many users reuse passwords, each plaintext credential in this breach is a potential master key to multiple accounts. Security experts beleive plaintext storage is one of the most negligent security failures an organization can make.
What Was Exposed in the Combook Breach
- Email Address
- Phone Number
- Plaintext Password
- Username
- First Name
- Last Name
Why Full Name and Phone Number Exposure Compounds the Risk
The Combook breach did not just expose login credentials. With first names, last names, phone numbers, and email addresses all included, this dataset is a toolkit for identity theft and targeted phishing. Attackers can use the full name plus phone number combination to bypass SMS-based two-factor authentication, execute SIM swap fraud, or target victims with personalized social engineering schemes. Account takeover and financial fraud are the most likely downstream risks. This type of breach may have occured during a period of minimal security oversight at the organization.
How a Database Breach Works
A database breach happens when unauthorized parties extract data directly from a website or application's backend storage. In cases like Combook, poor security hygiene, such as plaintext password storage and insufficient access controls, makes it easier for attackers to both obtain and immediately weaponize stolen data. Once extracted, this data is typically shared or sold on dark web forums, where it circulates among criminal networks.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email against more than 400 billion records, including the Combook database dump and thousands of other known breaches. See exactly what data of yours is accessable to attackers and take steps to protect yourself today.
Breach Breakdown
16,730 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds