If You Reuse Passwords, the Hurb Leak of 20 Million Records Should Worry You
HEROIC analysts flagged the Hurb breach after noticing a spike in dark web activity involving travel platform credentials. The breach occured in March 2019 and exposed 20,718,099 customer records from Hurb, a Brazilian online travel agency formerly known as Hotel Urbano. The data leaked includes email addresses, phone numbers, full names, IP addresses, birthdays, and password hashes stored using unsalted MD5, a combination that is accessable to attackers with even basic cracking tools.
Why Unsalted MD5 Passwords and Phone Numbers Are a Fraud Recipe
Unsalted MD5 hashes are among the easiest password formats to crack. Tools that reverse common MD5 hashes are freely available, and attackers use them to recover plaintext passwords within minutes. Add a phone number and birthday to the mix, and you have everything needed to impersonate someone in a customer service call, bypass two-factor authentication via SIM swapping, or access travel loyalty accounts. This data was recieved enthusiastically in dark web markets, especially by fraud rings targeting financial services and e-commerce platforms.
What Was Exposed in the Hurb Breach
- Email Address
- Phone Number
- First Name
- Last Name
- IP Address
- Password Hash
- Birthday
Why Reusing Your Hurb Password Could Cost You More Than a Trip
If you had a Hurb account in 2019 and you are still using that same password anywhere else, your accounts are at real risk. Credential stuffing attacks run cracked passwords automatically across banking apps, email providers, and online stores. And with a phone number and birthday also exposed, attackers have what they need to bypass account recovery systems. The risks here are not just beleived to be theoretical, they include identity theft, unauthorized purchases, and full account takeover across every platform where that password was reused.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to the backend systems where a company stores its user data. Travel agencies like Hurb handle large volumes of personal customer information, making them attractive targets. Attackers typically exploit known software vulnerabilities, poorly secured APIs, or stolen employee credentials to get in. Once inside, they can export the entire user database. The stolen data then gets sold on dark web forums, sometimes years after the original intrusion.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email against a database of over 400 billion compromised records, including the Hurb breach. Find out in seconds if your personal information is already circulating in underground markets and what you should do about it.
Breach Breakdown
20,718,099 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds