German Retailer Billerbeck Leaks 2,449 Plaintext Passwords
HEROIC analysts identified a data breach tied to Billerbeck, a German eCommerce retailer, first leaked on August 26, 2018. The exposed dataset contains 2,449 records, each pairing an email address with a plaintext password. The data surfaced on a cybercrime forum, where it remains available for anyone to read directly, no cracking required.
Why This Is Dangerous
Plaintext passwords are exposed exactly as the user typed them, with no hashing or encryption standing between the data and anyone who downloads it. That removes the biggest obstacle attackers normally face after a breach. Instead of spending time and computing power trying to crack a password, they can immediately use the email and password pairs from this leak to try logging into other accounts.
What Was Exposed
- Email addresses
- Plaintext passwords
Why This Matters
A leak of this size might look small next to headline-grabbing mega-breaches, but the risk to each person affected is just as real. Shoppers who used the same email and password on Billerbeck often use it elsewhere too, on email accounts, banking apps, or other retail sites. Attackers automate the process of testing these credentials across many services at once, a technique called credential stuffing, and every match can lead to account takeover, financial fraud, or identity theft.
How Database Breaches Turn Into Combolists
This incident is classified as both a database breach and a combolist. It began as a database breach, meaning attackers gained unauthorized access to Billerbeck's stored customer records and extracted them directly. From there, the email and plaintext password pairs were repackaged into a combolist, a stripped-down file format built specifically for automated login attempts against other websites. Once a combolist like this circulates on a cybercrime forum, it can be reused for years by different attackers.
Check If You Are Affected
If you have ever shopped with Billerbeck or reused a password across multiple online accounts, it is worth checking whether your information appears in this leak. HEROIC's free breach scanner searches a database of more than 400 billion leaked records, helping you find out where your data has been exposed so you can change your passwords before someone else uses them.
Breach Breakdown
2,449 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds