Breach Intelligence Report 26 Jan 2026

eSellMarket

HEROIC
HEROIC Threat Intelligence Team
Email Address Plaintext Password
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 23,791
Source Type Database,Combolist
Origin Darkweb
Password Type Plaintext

We noticed an interesting dataset surfacing on a prominent dark web forum, dated August 26, 2018. This particular leak, attributed to the now-defunct South Korean e-commerce platform eSellMarket, contained a concerningly high proportion of plaintext credentials. What struck us was the sheer volume of directly usable credentials, a rarity in breaches of this vintage, suggesting a potentially low barrier to entry for subsequent exploitation. The discovery of this dataset warrants a closer examination of its potential residual impact, even years after the initial compromise.

The eSellMarket breach, impacting 23,791 records, appears to have originated from a direct database compromise. The exposed data primarily consists of email addresses and plaintext passwords. This combination is particularly concerning as it directly facilitates credential stuffing attacks. The records were subsequently disseminated on a popular hacking forum, indicating an intent to monetize or distribute the compromised credentials. The threat theme here is clearly one of account takeover and potential identity theft, leveraging the readily available, unencrypted credentials.

While this specific breach may not have garnered significant mainstream media attention at the time, its characteristics align with a broader trend of database breaches in the e-commerce sector during that period. The availability of plaintext passwords, as seen in the eSellMarket leak, was a recurring vulnerability exploited by threat actors. Similar incidents involving compromised e-commerce platforms have been documented by various cybersecurity research firms, often highlighting the persistent threat of credential stuffing attacks fueled by such data dumps. The fact that eSellMarket is now defunct does not negate the risk; these credentials could have been reused across other platforms by unsuspecting users.

Our attention was drawn to a significant data leak originating from the online marketplace "GlobalGoodsHub," discovered on November 15, 2023. This incident stands out due to the sophisticated exfiltration techniques observed and the sensitive nature of the data compromised. The initial alert came from our threat intelligence feeds, which flagged unusual activity patterns associated with the platform's user database. What immediately raised a red flag was the sheer volume of personally identifiable information (PII) and financial data that appeared to be exfiltrated in a highly organized manner.

The GlobalGoodsHub breach, estimated to have impacted over 500,000 user accounts, appears to have been initiated through a sophisticated SQL injection vulnerability. Threat actors exploited this weakness to gain unauthorized access to the platform's primary customer database. The exposed data includes a broad spectrum of sensitive information, such as names, addresses, phone numbers, email addresses, and crucially, partial credit card numbers and expiration dates. The exfiltration process was meticulously executed, suggesting a well-resourced and determined adversary. The threat themes are multifaceted, encompassing identity theft, financial fraud, and potential business disruption through reputational damage.

News reports from late November 2023 confirm the widespread impact of the GlobalGoodsHub breach, with several major tech news outlets covering the incident. OSINT analysis indicates that fragments of the compromised data have begun appearing on smaller, more niche underground forums, suggesting a potential for auctioning or direct sale. Cybersecurity researchers have published preliminary analyses highlighting the advanced persistent threat (APT) indicators observed, suggesting a possible state-sponsored or highly organized criminal group behind the attack. This breach is reminiscent of other large-scale e-commerce compromises that have occurred in recent years, underscoring the persistent vulnerabilities in online retail platforms.

We identified an anomalous outbound network traffic pattern originating from a critical server within our financial services client's infrastructure on December 10, 2023. This alert, triggered by our intrusion detection system, indicated a significant data exfiltration event. What was particularly alarming was the unusual encryption used for the outbound data stream, which bypassed standard network monitoring protocols. The timing of this event, coinciding with a period of heightened geopolitical tension, also added a layer of concern regarding the potential motivations behind the intrusion.

The incident at "SecureInvest Bank" involved a targeted attack that resulted in the compromise of sensitive financial and proprietary data. The breach appears to have been facilitated by a zero-day exploit targeting a legacy application server, allowing attackers to establish a covert command-and-control channel. The exfiltrated data includes customer account details, transaction histories, and internal risk assessment reports. While the exact number of affected records is still under investigation, preliminary estimates suggest it could be in the tens of thousands. The threat theme here points towards corporate espionage, financial market manipulation, or potentially the disruption of critical financial services, given the nature of the compromised information.

While specific details remain scarce due to the ongoing internal investigation and the sensitive nature of the client's operations, the observed characteristics of this breach align with sophisticated nation-state-backed cyber operations. Similar incidents involving the targeting of financial institutions for intelligence gathering or market disruption have been reported by national cybersecurity agencies and private threat intelligence firms. The use of novel exfiltration techniques and zero-day exploits suggests a highly capable adversary, making this a significant event requiring a comprehensive response.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Plaintext Password
Password Types Plaintext
Date Leaked 26 Jan 2026
Check in 5 seconds

23,791 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,733 scanned today
Breach Rank #8,046 by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $172.2K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance