The Divalook Breach Handed Attackers 1,198 Plaintext Passwords to Use
HEROIC analysts uncovered the Divalook breach, which occured in September 2020 and exposed 1,198 user records from the Kenya-based electronics e-commerce platform. The compromised data included email addresses and plaintext passwords, meaning the credentials were stored without any hashing or encryption and were immediately accessable to anyone who obtained the database.
What the Divalook Breach Gave Attackers: Ready-to-Use Login Credentials
Plaintext passwords require zero effort to exploit. Every one of the 1,198 Divalook accounts handed attackers a working email and password combination that could be tested immediately against Gmail, social media platforms, banking apps, and any other service where the user reused that password. There is no cracking step, no waiting, no guessing. The credentials are ready to use the moment the database is obtained.
What Was Exposed in the Divalook Breach
- Email Address
- Plaintext Password
Why Even a Small Breach Like Divalook Enables Real Account Takeover
Scale does not determine severity when passwords are stored in plaintext. Each of the 1,198 Divalook records represents a real person whose email and exact password are seperate from any protection whatsoever. Credential stuffing tools can test these combinations across hundreds of services in minutes, making account takeover, identity theft, and financial fraud straightforward even from a small regional breach.
How a Database Breach Works
A database breach happens when an attacker gains unauthorized access to the backend data store of a website or application, often by exploiting software vulnerabilities, weak administrative passwords, or misconfigured servers. Once inside, the attacker exports user records. In Divalook's case, those records contained passwords stored as plain readable text rather than cryptographic hashes, meaning no additional processing was needed to use the stolen credentials.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across 400 billion leaked records to check whether your email address appears in the Divalook breach or other known leaks. Run your free check at HEROIC.com today.
Breach Breakdown
1,198 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds