The GatoPreto Breach Happened in April 2023. The Data Is Still Circulating Now.
HEROIC analysts found the GatoPreto customer database surfacing in underground markets in late April 2023. The Portuguese home furniture and decor e-commerce platform had approximately 114,000 records pulled from their systems, with 38,932 unique email addresses confirmed in the dataset. The data was clean and well-formatted, indicating a direct database export rather than a scraped or partially gathered collection. That kind of structured dump is more useful to attackers and tends to circulate more widely through criminal networks.
38,932 GatoPreto Customer Emails Are Now Fueling Phishing Campaigns
Attackers who obtain a list this size do not sit on it. Within days of a breach like this surfacing, the email list gets loaded into automated phishing tools and tested against other services. With full names paired to every address, the messages they send can be personalized and look entirely legitimate. A GatoPreto customer might recieve a convincing email appearing to come from a Portuguese retailer, a shipping company, or even a bank, because the attacker knows their name and that they shop online. That level of personalization dramatically increases the chance a victim clicks a malicious link or hands over login credentials.
What Was Exposed in the GatoPreto Breach
- Email addresses (38,932 unique)
- First names
- Last names
Why the GatoPreto Data Is Still Dangerous Today
Breach data does not expire. A list of names and email addresses from 2023 is just as usable in 2026 as it was the day it was stolen. People rarely change email addresses, and the personal information stays accurate for years. Attackers cross-reference new breach dumps against older ones to build richer profiles over time. If your GatoPreto email also appeared in seperate breaches that included passwords, attackers can now link your name, email, and password together into a single record. That kind of combined data is what enables account takeover, identity fraud, and targeted scams at scale. The timing of when a breach occured matters far less than whether your data is in circulation at all.
How Database Breaches Work
When an e-commerce platform like GatoPreto suffers a database breach, it usually starts with a vulnerability in the website's backend, such as an outdated plugin, an unsecured API endpoint, or a successful SQL injection attack through a product search or checkout form. Attackers probe these entry points systematically, and once they find one that works, extracting the customer table takes minutes. The resulting file is then packaged and shared across private Telegram groups and dark web forums. From there, it gets parsed, enriched with data from other breaches, and sold to whoever will pay for it.
Check If Your Data Was Exposed
HEROIC's free dark web scanner has indexed over 400 billion records from breaches worldwide, including the GatoPreto database dump. If you ever shopped at GatoPreto or used the same email address on other platforms, your information may already be in active use by threat actors. Run a free scan at HEROIC.com right now to find out exactly what data linked to your email address is out there and where it came from.
Breach Breakdown
38,932 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds