Plain Text Passwords. 3,444 Accounts. The FurnitureBook.co.uk Breach.
HEROIC analysts came across the FurnitureBook.co.uk breach while scanning a batch of aggregated eCommerce credential lists that surfaced in early 2018. The breach affected 3,444 accounts on this UK-based online furniture retailer, with records including email addresses and passwords stored in plaintext. While the record count is small, the presence of plaintext passwords means every single affected account was immediately accessable to anyone who obtained the data, with no technical hurdles at all.
How Plaintext Passwords From an eCommerce Breach Get Reused Across the Web
When a shopping site stores passwords as plain readable text, a data breach hands attackers a complete list of working login credentials with zero effort required. Criminals take those email and password pairs and run them through automated tools that test them against hundreds of other websites, looking for matches. If you used the same password on FurnitureBook.co.uk as you did on your email account, a bank login, or any other service, those accounts are now directly at risk. The small size of this breach does not reduce the individual danger at all.
What Was Exposed in the FurnitureBook.co.uk Breach
- Email Address
- Plaintext Password
Why Even Small eCommerce Breaches Create Big Problems for Shoppers
Most people beleive that only large breaches pose real risks, but smaller site leaks are frequently bundled into mass credential lists and used in automated attacks. If your email appears in this breach, attackers now have a plaintext password associated with your email address. They will try that combination on Gmail, PayPal, Amazon, online banking, and any other service they can think of. The risk is not limited to FurnitureBook.co.uk. It extends to every account where you used or reused that password, making credential stuffing, account takeover, and financial fraud all very real possibilities.
How Database Breaches Work
A database breach happens when an attacker finds a weakness in a website's system and copies the file containing all user account information. For eCommerce sites like FurnitureBook.co.uk, this typically means the attacker accesses the part of the system that stores customer logins. If the site stored passwords as plain text rather than using a secure hashing method, the attacker instantly has usable credentials for every account. The stolen data is then shared across dark web forums and credential stuffing marketplaces, where other criminals buy or download it and use it to attack other online services.
Check If Your Data Was Exposed
HEROIC provides a free breach scanner that checks your email against a database of over 400 billion leaked records, including the FurnitureBook.co.uk breach. Run a free scan at HEROIC right now to find out if your credentials are circulating on the dark web and learn what steps to take to protect yourself.
Breach Breakdown
3,444 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds