Our Analysts Found the Guia de Compra Leak on a Hacking Forum
HEROIC analysts found a dataset attributed to Guia de Compra, a Brazilian consumer information platform, shared on a hacking forum. Dated August 26, 2018, it contains 12,433 email addresses paired with Base64-encoded password hashes. This attribution has not been independently verified.
Why a Base64-Encoded Leak Still Poses a Risk
Base64 is not encryption, it's a reversible encoding format that anyone can decode in seconds with free online tools. A password stored this way offers essentially no protection once the underlying database is exposed, which is what appears to have happened here.
What Was Exposed
- Email addresses
- Password hashes (Base64-encoded)
Why This Matters
Because Base64 is trivial to reverse, the 12,433 passwords in this dataset should be treated as if they were exposed in plaintext. Anyone who reused one of these passwords elsewhere is at risk of credential stuffing and account takeover on other services.
How This Kind of Database Leak Spreads
Once a database like this is copied out, it's typically posted on a forum where other users can download, decode, and repackage it into ready-to-use combolists. From there, the data feeds automated login attempts against unrelated websites, far beyond the original platform.
Check If You Are Affected
Run a free scan with HEROIC's breach checker to see if your email address appears in this leak or any of the other 400 billion-plus records in HEROIC's breach database.
Breach Breakdown
12,433 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds