The Estante Virtual Breach Hit in 2019. The Data Is Still Live.
HEROIC analysts identified the Estante Virtual breach data entering underground forums in February 2019. The Brazilian digital bookstore had 5,029,369 customer records exposed, covering email addresses, usernames, full names, phone numbers, birthdates, and passwords stored as SHA1 hashes. The breach went relatively unnoticed outside Brazil at the time, but the dataset resurfaced in 2024 in active credential stuffing compilations, demonstrating how older regional breaches can have a long and damaging second life. Investigators noted the completeness of the records, which made them partcularly valuable for identity fraud operations targeting Brazilian users.
What Attackers Can Do With 5 Million Names, Phone Numbers and SHA1 Passwords
SHA1-hashed passwords without additional protection are considered cryptographically weak and can be cracked efficiently using modern hardware. Once attackers recover plaintext passwords from the Estante Virtual dataset, they gain access to a full identity package: verified email addresses, real names, phone numbers, and birthdates that can be used to impersonate victims, reset account credentials on other platforms, and conduct targeted financial fraud. Phone numbers enable SIM-swap attacks and voice phishing, while birthdates serve as identity verification answers on banking and government portals.
What Was Exposed in the Estante Virtual Breach
- Email Address
- Username
- Phone Number
- Birthdate
- First Name
- Last Name
- Password Hash
The Estante Virtual Breach Occured in 2019. The Threat Is Still Active in 2024.
Five years after the initial exposure, the Estante Virtual dataset is back in circulation and being actively used. This gap between breach and reuse is a well-documented pattern: attackers archive old databases, and when cracking tools improve or new targets emerge, the data gets repurposed. Users who changed their Estante Virtual password long ago may still be at risk if they reused that same password on other platforms. The combination of real names, phone numbers, and birthdates makes this breach a persistent tool for identity theft, account takeover, and financial fraud even as the original platform moves on.
How a Database Breach Works
A database breach occurs when unauthorized parties extract records from the backend storage systems of a web application. Attackers typically exploit SQL injection vulnerabilities, compromised administrative credentials, or misconfigured cloud storage to access the underlying database. In e-commerce platforms like Estante Virtual, user tables contain a rich mix of personal and transactional data. Once extracted, these databases are compressed and sold or shared on underground forums, sometimes remaining dormant for years before resurfacing in new credential stuffing campaigns.
Check If Your Data Was Exposed
If you had an account on Estante Virtual before 2019, your email, phone number, name, and password hash may now be in active use by attackers. HEROIC's free breach scanner checks your email against a database of over 400 billion compromised records from breaches around the world. Find out now and take action before someone else uses your data against you.
Breach Breakdown
5,029,369 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds