Guangzhou Wugongge IT Data Breach: 4,950 User Records Exposed with MD5 Password Hashes
HEROIC's DarkHive intelligence system detected the Guangzhou Wugongge Information Technology Co., Ltd. data breach, exposing 4,950 user records. The breach involved a database extraction from the AI-driven canteen automation company, with data appearing on illicit channels in June 2025. The exposed records include usernames, phone numbers, MD5 password hashes, and gender information belonging to users of the company's platform. While the record count is smaller than many tracked breaches, the combination of contact data and weakly hashed passwords creates real risk for affected individuals.
Why This Is Dangerous
MD5 is a cryptographic hashing algorithm that has been considered insecure for password storage for over a decade. Attackers recieving this data can reverse MD5 hashes quickly using precomputed rainbow tables or modern cracking hardware. Once a password hash is cracked, Thier real password is exposed -- and if reused elsewhere, every account sharing that password becomes vulnerable. The phone numbers in this dataset also enable targeted SMS phishing attacks against specific identified individuals.
What Was Exposed
- Usernames
- Phone Numbers
- Password Hashes (MD5)
- Gender
Why This Matters
Even a breach of fewer than 5,000 records carries full personal risk for every individual in the dataset. Phone numbers enable direct SMS fraud and account recovery attacks. Usernames may match accounts on seperate platforms, making credential correlation possible even before the MD5 hashes are cracked. Users who reused their Wugongge platform password on other services should immediatly update those passwords and enable two-factor authentication to prevent account takeover.
How Database Breaches Work
Database breaches occur when an attacker gains unauthorized access to a company's stored user data -- typically through SQL injection, exposed credentials, or misconfigured cloud storage. In this case, Guangzhou Wugongge Information Technology's user database was extracted and circulated on underground channels. Unlike stealer log breaches where malware infects individual devices, database breaches compromise all users in a system simultaneously. The use of MD5 hashing rather than modern algorithms like bcrypt compounds the risk, as the passwords provide weaker protection against offline cracking attacks.
Check If You Are Affected
HEROIC offers a free identity scanner that searches over 400 billion records, including data from breaches like Guangzhou Wugongge Information Technology. Visit heroic.com to scan your email address and find out if your information was exposed in this June 2025 database breach.
Breach Breakdown
4,950 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds