The eStoreKo Dump: 14,799 Plaintext Passwords and Emails Hit the Dark Web
HEROIC analysts identified a database breach affecting eStoreKo, an e-commerce platform based in the Philippines. The breach, dated June 2021, exposed 14,799 user records. The dataset is particularly alarming because passwords were stored in plaintext, meaning they were never hashed or encrypted at all. Every user who recieved this exposure had their actual login credentials sitting in the open, ready for immediate use by any attacker who accessable the dump.
Why Plaintext Passwords in the eStoreKo Breach Are Immediately Dangerous
Unlike breaches where passwords are protected by hashing, plaintext storage means zero cracking is required. An attacker who obtained this database could begin testing credentials against other platforms, including email providers, online banking, and social media, within minutes. Because eStoreKo is an e-commerce platform, exposed users may have reused the same password on accounts that store payment information or shipping addresses, creating direct financial risk.
What Was Exposed in the eStoreKo Breach
- Email Address
- Plaintext Password
Why Even a Small Breach Creates Outsized Credential Stuffing Risk
Although 14,799 records is a smaller breach by volume, the data quality is seperate from scale in terms of risk. Every single credential pair is immediately usable, making this a high-yield dataset for credential stuffing attacks. Attackers prioritize plaintext dumps because they eliminate the bottleneck of cracking, allowing for faster, more scalable account takeover campaigns across banking, email, and retail platforms where password reuse is common. Victims face risks of identity theft and financial fraud.
How a Database Breach Works
A database breach occured when an attacker gains unauthorized access to a web application's backend data store, often through SQL injection, server misconfigurations, or compromised credentials. Once access is obtained, user records can be exported in bulk within seconds. The stolen data is then posted or sold in underground markets, where other criminals use it immediately for account takeover and fraud campaigns.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks more than 400 billion records, including the eStoreKo dataset, to tell you instantly whether your email address or passwords appeared in this or any other known breach. Run a free check at HEROIC now and find out exactly what information of yours is circulating online.
Breach Breakdown
14,799 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds