IceNEO Data Breach: 33,296 Polish eCommerce Records (2018)
Poland's Defunct eCommerce Platform and Its Crackable Credentials
IceNEO was a Polish eCommerce platform that has since gone dark. Its 2018 breach left 33,296 users' credentials circulating on underground forums -- a significant dataset for a regional retailer. What makes this breach particulary notable from a security standpoint is the dual hash types: MD5 and pHpass. Both are vulnrable to modern cracking techniques, and the combination suggests different parts of the platform's database were protected by different hashing implementations, possibly indicating a CMS migration or mixed technology stack at the time of the breach. This architectural inconsistency amplified the breach's exploitability.
IceNEO (August 2018): Breach Summary
- Records Exposed: 33,296
- Data Types: Email addresses, MD5 and pHpass password hashes
- Breach Type: Database dump / Combolist
- Country Affected: Poland
- Date Leaked: August 26, 2018
Mixed Hash Types: A Red Flag for Platform Security
Finding both MD5 and pHpass hashes in the same database dump is a signal worth analyzing. MD5 without salting is fully rainbow-tableable -- common passwords crack instantly against precomputed tables with no GPU time required. pHpass, while slower to crack due to its iterated structure, is routinely defeated by GPU-accelerated tools running standard wordlists. The presence of both hash types in IceNEO's database suggests the platform went through at least one major software update that changed its password hashing implementation, but failed to migrate or re-hash existing passwords. This assoiciated risk means some users were substantially less protected than others based solely on when they created their accounts -- an architectural failure that compounded the breach's overall impact.
Polish eCommerce and the Long Tail of Credential Exposure
Poland's eCommerce sector grew significantly through the 2010s, with many platforms adopting consumer shopping behaviors from established Western markets. IceNEO's 33,296 exposed accounts represent real Polish consumers who were shopping online when GDPR-era data protection wasn't yet in force. Those credentials, even years old, remain valuable for attackers targeting Polish consumers on still-active platforms: banking portals, retail sites, and subscription services where the same email and password may have been reused. Defunct retailer breaches are particularly persistent in the combolist ecosystem because the company can't coordinate any cleanup response -- the data simply circulates indefinitely.
Poland's Contribution to the August 26, 2018 Combolist Release
IceNEO appeared alongside more than ten other breached platforms on August 26, 2018 -- a mass release spanning Poland, Germany, Thailand, the United States, Italy, Ireland, Japan, Nepal, and the Netherlands. Poland contributed multiple breaches to the broader August 26 cluster, reflecting the wide reach of the mass release across European markets and beyond. Each individual database looks modest in isolation; aggregated, the August 26 releases represent a substantial credential injection into underground combolist pipelines.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records -- including Polish eCommerce databases like IceNEO. If you've shopped on Polish retail sites in the 2010s, your email and password may be in active circulation. A scan takes seconds and can flag whether your credentials are being tested against European consumer platforms right now.
Breach Breakdown
33,296 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds