Breach Intelligence Report 13 Sep 2025

IceNEO Data Breach: 33,296 Polish eCommerce Records (2018)

HEROIC
HEROIC Threat Intelligence Team
Email Address Password Hash
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 33,296
Source Type Database,Combolist
Origin Darkweb
Password Type MD5,Other

Poland's Defunct eCommerce Platform and Its Crackable Credentials

IceNEO was a Polish eCommerce platform that has since gone dark. Its 2018 breach left 33,296 users' credentials circulating on underground forums -- a significant dataset for a regional retailer. What makes this breach particulary notable from a security standpoint is the dual hash types: MD5 and pHpass. Both are vulnrable to modern cracking techniques, and the combination suggests different parts of the platform's database were protected by different hashing implementations, possibly indicating a CMS migration or mixed technology stack at the time of the breach. This architectural inconsistency amplified the breach's exploitability.


IceNEO (August 2018): Breach Summary

  • Records Exposed: 33,296
  • Data Types: Email addresses, MD5 and pHpass password hashes
  • Breach Type: Database dump / Combolist
  • Country Affected: Poland
  • Date Leaked: August 26, 2018

Mixed Hash Types: A Red Flag for Platform Security

Finding both MD5 and pHpass hashes in the same database dump is a signal worth analyzing. MD5 without salting is fully rainbow-tableable -- common passwords crack instantly against precomputed tables with no GPU time required. pHpass, while slower to crack due to its iterated structure, is routinely defeated by GPU-accelerated tools running standard wordlists. The presence of both hash types in IceNEO's database suggests the platform went through at least one major software update that changed its password hashing implementation, but failed to migrate or re-hash existing passwords. This assoiciated risk means some users were substantially less protected than others based solely on when they created their accounts -- an architectural failure that compounded the breach's overall impact.


Polish eCommerce and the Long Tail of Credential Exposure

Poland's eCommerce sector grew significantly through the 2010s, with many platforms adopting consumer shopping behaviors from established Western markets. IceNEO's 33,296 exposed accounts represent real Polish consumers who were shopping online when GDPR-era data protection wasn't yet in force. Those credentials, even years old, remain valuable for attackers targeting Polish consumers on still-active platforms: banking portals, retail sites, and subscription services where the same email and password may have been reused. Defunct retailer breaches are particularly persistent in the combolist ecosystem because the company can't coordinate any cleanup response -- the data simply circulates indefinitely.


Poland's Contribution to the August 26, 2018 Combolist Release

IceNEO appeared alongside more than ten other breached platforms on August 26, 2018 -- a mass release spanning Poland, Germany, Thailand, the United States, Italy, Ireland, Japan, Nepal, and the Netherlands. Poland contributed multiple breaches to the broader August 26 cluster, reflecting the wide reach of the mass release across European markets and beyond. Each individual database looks modest in isolation; aggregated, the August 26 releases represent a substantial credential injection into underground combolist pipelines.


Check If Your Credentials Were Exposed

HEROIC's free breach scanner searches across more than 400 billion exposed records -- including Polish eCommerce databases like IceNEO. If you've shopped on Polish retail sites in the 2010s, your email and password may be in active circulation. A scan takes seconds and can flag whether your credentials are being tested against European consumer platforms right now.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Password Hash
Password Types MD5,Other
Date Leaked 13 Sep 2025
Check in 5 seconds

33,296 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,451 scanned today
Breach Rank #6,912 by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $240.9K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance