If You Shopped at Eiger Indo Store, Your Name and Email May Be on the Dark Web
HEROIC analysts found a dataset tied to Eiger Indo Store, an Indonesian outdoor gear and adventure apparel eCommerce platform now operating as Eiger Adventure, circulating on dark web forums in May 2023. The breach exposed 22,427 customer records containing email addresses, first names, and last names. While no passwords were included in this particular dump, the personal data exposed is sufficient to fuel targeted phishing attacks and identity fraud against outdoor enthusiasts who shopped on the platform.
What Attackers Can Do With Names and Emails Alone
Many people beleive a breach is only serious when passwords are included. That is not true. A dataset of 22,427 confirmed email and name combinations is a ready-made phishing list. Attackers can send personalized emails using the recipient's real name, referencing their activity on a known brand they actually used, which dramatically increases the chances the target will click a malicious link, download a fake invoice, or hand over credentials to a spoofed login page.
What Was Exposed in the Eiger Indo Store (Eiger Adventure) Breach
- Email addresses
- First names
- Last names
Why PII-Only Breaches Still Lead to Identity Theft and Account Takeover
Personal identifiable information without passwords is still highly accessable for downstream fraud. Name and email combinations are routinely cross-referenced with other leaked datasets to build complete profiles. If your email address and name from the Eiger Indo Store breach match data from another breached service that did include a password, attackers can connect those records and compromise accounts you may have thought were unrelated. This is how credential stuffing campaigns grow in scope over time.
How eCommerce Breaches Like This Occured
Platforms like Eiger Indo Store typically store customer registration data in a backend database that handles orders and accounts. Attackers identify exposed database interfaces, API endpoints, or admin panels through automated scanning tools, then exploit vulnerabilities to extract customer tables. The extracted data is compressed and uploaded to dark web markets within hours of a successful intrusion. For a mid-sized regional retailer, detection can take weeks if internal monitoring is limited.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email against more than 400 billion compromised records, including data from the Eiger Indo Store breach. If you ever shopped on the platform or created an account, run a free scan at HEROIC.com to see if your information was part of this or any other known breach.
Breach Breakdown
22,427 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds