Fruto Salvaje
We noticed a curious pattern of email addresses surfacing on a public hacking forum, a common occurrence that often signals a compromised dataset. What struck us was the seemingly low volume of data, yet its origin pointed to a niche e-commerce platform, Fruto Salvaje, based in Colombia. The leak, dated August 26, 2018, comprised primarily email addresses, a staple for credential stuffing and phishing campaigns. The relatively small number of records, just under 13,000, initially suggested a minor incident, but the context of its dissemination on a well-trafficked forum warrants closer examination of its potential downstream impact.
The breach originated from a database compromise on the Fruto Salvaje e-commerce platform, resulting in the exposure of approximately 12,978 records. The primary data exfiltrated was email addresses, with an estimated 13,000 unique entries identified. This dataset was subsequently published on a popular hacking forum, suggesting its immediate availability to threat actors seeking to build combolists or target users with phishing attacks. The nature of the leak, a direct database dump, indicates a potentially significant vulnerability within the platform's data storage or access controls at the time of the incident. The fact that this data is still accessible and potentially being utilized years after its initial leak highlights the persistent threat posed by older, unaddressed compromises.
While this specific incident did not generate widespread mainstream news coverage at the time of its discovery, similar breaches of e-commerce platforms are frequently reported. OSINT investigations into Fruto Salvaje's security posture around August 2018 did not reveal any immediate public advisories or known vulnerabilities that directly correlate with this database compromise. However, the methodology of data exposure aligns with common tactics observed in breaches where databases are exfiltrated and then repackaged into combolists for resale or distribution within illicit communities. Research into the evolution of combolist creation and distribution on hacking forums confirms that datasets of this size and type are consistently leveraged for large-scale credential stuffing attacks against various online services.
Breach Breakdown
12,978 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds