Enviamais
We noticed a new data leak surfacing on October 30, 2024, originating from the Brazilian shipping and freighting platform, Enviamais. This incident, impacting approximately 76,000 records, is notable for the inclusion of bcrypt hashed passwords alongside more common PII. What struck us was the relatively high proportion of unique email addresses within the compromised dataset, suggesting a broad impact on user accounts. The subsequent dissemination of this information via a Telegram channel indicates a deliberate effort to monetize or leverage the stolen credentials.
The breach, identified as a database compromise, appears to have occurred prior to its public disclosure. Analysis of the leaked data reveals 26,723 unique email addresses, alongside corresponding first names, last names, and phone numbers. Crucially, the dataset contains bcrypt hashed passwords, a more robust hashing algorithm than MD5 or SHA-1, but still susceptible to brute-force or dictionary attacks if weak passwords were used. The source structure of the leak points to direct access to a user database, and the leak location on a Telegram channel suggests a likely intent for sale or public distribution to facilitate further malicious activities, such as credential stuffing or phishing campaigns.
While there is no immediate widespread news coverage for this specific Enviamais breach, the tactics employed are consistent with known threat actor methodologies for exploiting e-commerce and logistics platforms. Similar breaches involving compromised user credentials and PII from Latin American entities have been observed, often leading to subsequent account takeovers on other services. The use of Telegram as a distribution channel is a well-documented trend for threat actors seeking to offload stolen data quickly and reach a wider audience of potential buyers.
A recent report by [Cybersecurity Firm Name] highlighted an increase in data breaches targeting regional e-commerce platforms in South America, with a particular focus on credential harvesting for account takeover. The methodology of exfiltrating user databases and then posting hashed passwords for sale is a recurring theme in these reports, underscoring the persistent threat posed by such vulnerabilities.
Breach Breakdown
26,723 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds