Your Data May Already Be Compromised. The ePrice Taiwan Breach Exposed 459K Records.
HEROIC analysts identified the ePrice Taiwan breach, dating to January 2021, which occured when attackers compromised the Taiwanese electronics retailer's database. The breach exposed 459,295 records that were recieved by criminal marketplaces and included email addresses, phone numbers, plaintext passwords, bcrypt password hashes, usernames, first names, last names, IP addresses, gender, and birthdays.
Plaintext Passwords Plus Birthdays and IP Addresses Make This Breach Immediately Actionable
This breach contains some of the most dangerous combinations possible: plaintext passwords require no cracking, and birthdays combined with names and phone numbers provide everything needed to bypass identity verification on financial and government platforms. IP addresses allow attackers to geolocate victims and tailor phishing attacks, while the bcrypt hashes, though slower to crack, remain a persistent threat. Every data point in this breach is accessable and usable by attackers right now.
What Was Exposed in the ePrice Taiwan Breach
- Email Address
- Phone Number
- Plaintext Password
- Password Hash
- Username
- First Name
- Last Name
- IP Address
- Gender
- Birthday
Why a Breach This Comprehensive Enables Long-Term Identity Fraud
When an attacker holds a victim's name, birthday, phone number, email, gender, and working password in a single record, the damage extends far beyond the original platform. This data profile is partcularly valuable for identity theft, account takeover across multiple services, SIM swapping, and targeted financial fraud. Even users who change their ePrice password remain at risk because the surrounding PII cannot be reset. Credential stuffing campaigns using this data can remain active for years after the initial breach.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a company's stored records, typically by exploiting vulnerabilities in web applications or database services. The attacker then copies the records before the compromise is detected. In cases involving plaintext password storage, as with ePrice Taiwan, the failure to apply basic security controls transforms a data breach into an immediate credential compromise for every affected user.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches over 400 billion records, including the ePrice Taiwan breach, to tell you whether your email and personal data are already circulating among attackers. Visit HEROIC.com to run a free check on your email today.
Breach Breakdown
459,295 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds