Detalles Falabella Breach: 29,004 Spanish Floral Gift Accounts Exposed (2018)
Flowers, Gifts, and a Data Breach Nobody Saw Coming
Detalles Falabella sold flower arrangements and personalized gifts -- the kind of platform people use for birthdays, anniversaries, and special occasions. It's not the site you'd expect to find on a breach list. But in August 2018, 29,004 customer accounts from this Spanish floral eCommerce platform were exposed, with email adresses and MD5-hashed passwords leaking from a database that held far more than just login credentials.
Detalles Falabella (August 2018): Breach Summary
- Records Exposed: 29,004
- Data Types: Email addresses, MD5 password hashes
- Breach Type: Database breach
- Country Affected: Spain
- Date Leaked: August 21, 2018
Gift Platforms Know More Than You Think
eCommerce platforms selling gifts and floral arrangements accumulate a specific kind of personal data that most breaches don't highlight: the recipient. Gift platforms typically store not just the buyer's credentials, but delivery addresses, recipient names, occasion notes, and sometimes personal messages. When an attacker gains access to a gift eCommerce account, they're not just getting an email and password -- they're getting a map of the buyer's personal relationships. Birthdays, anniversaries, and loved ones' adresses. This information is usable for social engineering, targeted phishing, and identity verification bypass in ways that go well beyond credential stuffing.
MD5: Still Getting Things Wrong in 2018
Detalles Falabella stored passwords using MD5 -- an algorithm the security industry abandoned for password hashing well before 2018. MD5 hashes are vulnerable to rainbow table attacks, precomputed lookup tables that can reverse common password hashes in seconds without any brute-force computation. For a consumer-facing eCommerce platform handling delivery informaton and personal occasion data, MD5 password storage represents a security failure compunded by the sensitivity of the surrounding data. Crakcing the passwords wasn't the end of the risk -- it was the beginning.
Spain's Second Breach in the August 2018 Wave
Detalles Falabella was not Spain's only appearance in the August 2018 breach cluster. Europreven Malaga, a Spanish workplace safety and occupational health platform, surfaced three days later on August 24 -- making Spain one of the more heavily represented countries in this sustained multi-day release event. The two Spanish breaches represent very different demographics: Europreven Malaga's B2B compliance professionals versus Detalles Falabella's consumer gift buyers. Both ended up in the same data distribution wave, a reminder that breach aggregators don't discriminate by sector or audience.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records -- including eCommerce platforms, gift services, and consumer retail sites. If you've ever registered on Detalles Falabella or similar platforms, check now to see if your data is circulating in breach databases.
Breach Breakdown
29,004 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds