What Hackers Can Do With the Gumac Breach: No Password Needed
HEROIC analysts identified a dataset linked to Gumac, a Vietnamese women's fashion retailer, appearing on a dark web forum on December 24, 2023. The exposed records covered 77,591 customers and contained no passwords — but that does not make this breach safe to ignore. What was leaked instead is a detailed personal profile for each affected user: full name, email address, phone number, and birthday. For skilled social engineers and identity fraudsters, that combination is more than enough to cause serious harm.
What Attackers Can Do With Your Name, Phone, Email, and Birthday
Many people assume a breach is only dangeous if passwords are included. The Gumac leak shows why that thinking is wrong. With a full name, birthday, phone number, and email address, an attacker can craft convincing phishing messages that appear to come from Gumac or any other brand the victim shops with. They can attempt to bypass SMS-based two-factor authentication by impersonating the victim with a carrier. They can answer common security questions to reset account passwords. And they can combine this data with information from other breaches to build even richer fraud profiles. The absense of passwords does not reduce the risk — it just changes the attack method.
What Was Exposed
- Email Address — primary target for phishing and account recovery attacks
- Phone Number — enables SMS fraud, SIM swapping, and vishing calls
- First Name and Last Name — makes social engineering messages convincing and personal
- Birthday — used to verify identity with banks, carriers, and online services
Why Personal Identity Data Fuels Identity Theft
Identity theft does not require a stolen password. It requires enough personal detail to convince a company or institution that the attacker is you. Birthdates, phone numbers, and full names are routinely used as identity verification factors by banks, mobile carriers, government services, and ecommerce platforms. Attackers who acquire this data can initiate fraudulent account changes, open new lines of credit, or redirect financial accounts — all without ever needing a password. Fashion retail platforms like Gumac often attract loyal, repeat customers whose personal details are stored long-term, making their data particularly valueable to identity fraudsters.
How Database Breaches Like This Happen
Database breaches at retail companies typically occur through one of several routes: SQL injection attacks that exploit weak input validation on web forms or APIs, unauthorized access using compromised employee credentials, or exploitation of unpatched vulnerabilities in ecommerce platforms and plugins. Once inside, attackers can export customer tables quietly and quickly. In many cases, the breach is not discovered for weeks or months after the data has already appeared for sale on criminal forums. The Gumac data surfaced on December 24, 2023 — and given the typical timeline from breach to discovery, the original intrusion likely occured well before that date.
Check If Your Information Was Exposed
HEROIC tracks over 400 billion records across thousands of known data breaches, including the Gumac dataset. If you shopped at Gumac or used the same email address or phone number with other services, your information may be in circulation on criminal markets right now. Visit heroic.com to check your exposure for free and take steps to protect your identity before attackers act on the data.
Breach Breakdown
77,591 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds