212,482 Email Addresses From Douglas Exposed on the Dark Web
HEROIC found the Douglas database breach dated March 3, 2024, exposing 212,482 records including email addresses, first and last names, gender, and SHA-256 password hashes from douglas.bg, a Bulgarian online store of the Douglas beauty and cosmetics brand.
Why the Douglas Breach Is Dangerous
SHA-256 hashed passwords without proper salting are vulnerable to brute-force and rainbow table attacks, especially for commonly used passwords. Combined with full names, email addresses, and gender information, this data enables credential stuffing, targeted phishing campaigns, and identity fraud against Douglas customers.
What Was Exposed in the Douglas Leak
- Email Address
- First Name
- Last Name
- Password Hash
- Gender
Why This Douglas Data Puts You at Risk
If your SHA-256 hash is cracked, attackers gain your password and can attempt it across email, banking, and other shopping platforms. Your full name, gender, and email address also fuel personalized phishing messages impersonating Douglas, increasing the likelihood of further account compromises.
How Database Breaches Work
Database breaches occur when attackers exploit vulnerabilities in a website or application to gain unauthorized access to the underlying database. Once inside, they extract stored records in bulk, including personal identifiers and hashed credentials. The stolen records are then sold or posted publicly on criminal forums.
Check If Your Data Was Exposed
HEROIC operates one of the world's largest breach databases, covering more than 400 billion leaked records. Use HEROIC's free breach scanner to check if your email address or credentials appeared in the Douglas leak or thousands of other breaches in our database.
Breach Breakdown
212,482 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds