Your Data Is at Risk. The FlexBooker Breach Exposed 2.7M Records.
HEROIC analysts flagged the FlexBooker breach during a review of cloud-related data exfiltration incidents. On December 23, 2021, attackers who had compromised an account within FlexBooker's AWS infrastructure gained access to user databases, exposing the personal and credential data of 2,790,792 users. The stolen records were recieved by criminal actors and include email addresses, password hashes, phone numbers, full names, and password salts, providing a detailed profile for each affected user.
How Leaked Password Hashes and Salts Enable Account Takeover
FlexBooker stored passwords using Base64-encoded hashes, but with the salt values also exposed, attackers have everything needed to crack those hashes efficiently. Once cracked, the plaintext passwords can be tested against email providers, banking portals, and other platforms in credential stuffing attacks. With full names and phone numbers also in the dataset, attackers can mount highly personalized phishing campaigns that are accessable and convincing to even cautious users.
What Was Exposed in the FlexBooker Breach
- Email Address
- Password Hash
- Phone Number
- First Name
- Last Name
- Salt
Why the FlexBooker Breach Carries Lasting Risk for Millions
Nearly 2.8 million users are at risk of credential stuffing, account takeover, and identity theft from this single breach. The combination of hashed passwords with salts means that even seperate accounts using the same email are at risk if password reuse is present. Attackers routinely use breach data like this to build persistent access into user accounts across financial, healthcare, and e-commerce platforms, making this a long-term exposure risk well beyond the original breach date.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a company's stored user data, often by exploiting compromised cloud credentials, weak access controls, or misconfigured services. In cloud environments, a single compromised admin account can give attackers access to entire data stores. The attacker then exports user records in bulk, which are later sold or traded on dark web forums.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion records, including data from the FlexBooker breach. Scan your email for free at HEROIC.com to find out if your password hash or personal information is in criminal hands and what steps to take immediately.
Breach Breakdown
2,790,792 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds