18,000 Records From the GetHere Database Breach Exposed Online
HEROIC analysts recieved intelligence on a data exposure tied to GetHere, an Indian platform, dated August 18, 2022. The breach surfaced approximately 18,000 records containing 99 unique email addresses, along with phone numbers, full names, and MD5 hashed passwords. The combination of personal identifiers and password hashes in a single dump makes this incident partcularly dangerous for affected users who may reuse credentials across multiple services.
Why MD5 Password Hashes Put GetHere Users at Risk
Attackers who obtain MD5 hashed passwords can run them through precomputed rainbow tables or brute-force tools and recover the original plaintext passwords within minutes. When those cracked passwords are paired with the email addresses and phone numbers also exposed in this breach, criminals gain everything they need to take over accounts on other platforms. This type of credential exploitation has occured repeatedly in large-scale account takeover campaigns targeting users of Indian digital services.
What Was Exposed in the GetHere Breach
- Email Address
- Phone Number
- Password Hash (MD5)
- First Name
- Last Name
Real-World Risks From This Exposure
Full names, phone numbers, and email addresses together form a profile that is accessable to fraudsters for phishing, SIM swapping, and social engineering attacks. Credential stuffing tools can automatically test cracked passwords against banking apps, email providers, and e-commerce sites. Users who received no breach notification remain unaware their login details may already be in active use by threat actors operating in underground markets.
How a Database Breach Works
A database breach occurs when attackers gain unauthorized access to a backend data store, typically by exploiting a SQL injection vulnerability, a misconfigured server, or stolen administrative credentials. Once inside, they extract structured records in bulk. The resulting dump is then traded or sold on dark web forums. MD5 hashing offers minimal protection because it was designed for speed, not security, making it trivial to reverse with modern hardware.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion records to tell you instantly whether your email address appeared in the GetHere breach or thousands of other known exposures. Run a free check at HEROIC.com to see exactly what data of yours is circulating on the dark web and get steps to secure your accounts before attackers act.
Breach Breakdown
99 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds