The Evdebir Breach: 6,030 Email and Password Pairs Surface Online
HEROIC analysts identified a dataset tied to Evdebir, a now defunct e-commerce platform based in Turkey, dated to August 26, 2018. The exposed information includes 6,030 records containing email addresses along with password hashes and their associated salts. Evdebir has not independently confirmed this breach, so the details below reflect what analysts observed in the leaked data itself.
Why This Is Dangerous
Even a modest dataset like this one carries real risk. Email addresses paired with password data give attackers a starting point to test those same credentials against other sites, a technique called credential stuffing. Because passwords are so often reused across multiple accounts, a small leak from an obscure Turkish retailer in 2018 can still open the door to someone's email, banking, or social media account today.
What Was Exposed
- Email addresses
- Password hashes
- Password salts
Why This Matters
Salted MD5 hashes are harder to crack in bulk than unsalted ones, but they are not unbreakable. With enough computing power, attackers can still recover original passwords one at a time, especially weak or common ones. Anyone who reused an Evdebir password on another account, particularly an email or banking login, faces a real risk of account takeover, financial fraud, or identity theft if that password is cracked.
How Database and Combolist Leaks Work
This incident is categorized as a database breach that has also circulated as part of a combolist, a compiled list of email and password pairs traded among cybercriminals. These lists are typically built from stolen databases like this one and then bundled with data from other breaches, making it easier for attackers to run automated login attempts across thousands of websites at once.
Check If You Are Affected
Use HEROIC's free breach scanner to check whether your email address appears in this leak or any of the more than 400 billion records in HEROIC's breach database. If a match turns up, change that password immediately, avoid reusing it anywhere else, and consider a password manager to keep every account's credentials unique.
Breach Breakdown
6,030 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds