Breach Intelligence Report 25 Jul 2022

The Estante Virtual Breach Hit in 2019. The Data Is Still Live.

HEROIC
HEROIC Threat Intelligence Team
Email Address Username Phone Number Birthdate First Name Last Password Hash
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 5,029,369
Source Type Database
Origin Darkweb
Password Type SHA1

HEROIC analysts identified the Estante Virtual breach data entering underground forums in February 2019. The Brazilian digital bookstore had 5,029,369 customer records exposed, covering email addresses, usernames, full names, phone numbers, birthdates, and passwords stored as SHA1 hashes. The breach went relatively unnoticed outside Brazil at the time, but the dataset resurfaced in 2024 in active credential stuffing compilations, demonstrating how older regional breaches can have a long and damaging second life. Investigators noted the completeness of the records, which made them partcularly valuable for identity fraud operations targeting Brazilian users.


What Attackers Can Do With 5 Million Names, Phone Numbers and SHA1 Passwords

SHA1-hashed passwords without additional protection are considered cryptographically weak and can be cracked efficiently using modern hardware. Once attackers recover plaintext passwords from the Estante Virtual dataset, they gain access to a full identity package: verified email addresses, real names, phone numbers, and birthdates that can be used to impersonate victims, reset account credentials on other platforms, and conduct targeted financial fraud. Phone numbers enable SIM-swap attacks and voice phishing, while birthdates serve as identity verification answers on banking and government portals.


What Was Exposed in the Estante Virtual Breach

  • Email Address
  • Username
  • Phone Number
  • Birthdate
  • First Name
  • Last Name
  • Password Hash

The Estante Virtual Breach Occured in 2019. The Threat Is Still Active in 2024.

Five years after the initial exposure, the Estante Virtual dataset is back in circulation and being actively used. This gap between breach and reuse is a well-documented pattern: attackers archive old databases, and when cracking tools improve or new targets emerge, the data gets repurposed. Users who changed their Estante Virtual password long ago may still be at risk if they reused that same password on other platforms. The combination of real names, phone numbers, and birthdates makes this breach a persistent tool for identity theft, account takeover, and financial fraud even as the original platform moves on.


How a Database Breach Works

A database breach occurs when unauthorized parties extract records from the backend storage systems of a web application. Attackers typically exploit SQL injection vulnerabilities, compromised administrative credentials, or misconfigured cloud storage to access the underlying database. In e-commerce platforms like Estante Virtual, user tables contain a rich mix of personal and transactional data. Once extracted, these databases are compressed and sold or shared on underground forums, sometimes remaining dormant for years before resurfacing in new credential stuffing campaigns.


Check If Your Data Was Exposed

If you had an account on Estante Virtual before 2019, your email, phone number, name, and password hash may now be in active use by attackers. HEROIC's free breach scanner checks your email against a database of over 400 billion compromised records from breaches around the world. Find out now and take action before someone else uses your data against you.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Username,Phone Number,Birthdate,First Name,Last Name,Password Hash
Password Types SHA1
Date Leaked 25 Jul 2022
Check in 5 seconds

5,029,369 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,664 scanned today
Breach Rank #665 by affected users
Impact Score
40
sensitivity + scale + recency
Est. Financial Impact $36.4M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance