Women Shoppers Targeted: ildBoutique Breach Exposed 7,043 Accounts
HEROIC analysts uncovered a database breach affecting ildBoutique, an Israeli e-commerce platform focused on women's apparel operating at ildboutique.manzalab.com. The breach occured on July 30, 2022 and exposed 7,043 unique user records. What makes this incident partcularly serious is the combination of data types exposed: alongside email addresses, the dump includes full names, birthdays, and a mix of both bcrypt-hashed and plaintext passwords stored side by side in the same database.
Mixed Password Storage in the ildBoutique Breach Doubles the Risk
When a database contains both bcrypt hashes and plaintext passwords, attackers target the plaintext accounts first for immediate credential stuffing, then invest cracking effort in the hashed accounts. Customers who recieved plaintext storage have their passwords fully exposed with no barrier, while those with bcrypt hashes face offline dictionary attacks. Combined with real names and birthdays, attackers can craft highly personalized phishing messages that are far more convincing than generic scam emails.
What Was Exposed in the ildBoutique Breach
- Email Address
- Password Hash
- Plaintext Password
- First Name
- Last Name
- Birthday
Why Birthdays and Full Names Make This Breach More Dangerous
Most breaches expose only email and password, but ildBoutique's leak also includes full names and birthdays. This data combination is accessable to identity fraud schemes that require knowledge-based authentication answers, birthday verification, or name-matched phishing. Account takeover attempts on banking apps, government portals, and healthcare services all become more likely when an attacker knows the target's full name and date of birth alongside a working email address.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a backend data store, typically through SQL injection, insecure direct object references, or compromised server credentials. The attacker exports the user table, which in ildBoutique's case contained personally identifiable information alongside authentication data. The resulting dump is then distributed across underground forums and data markets, where it can be purchased and used for years after the original incident.
Check If Your Data Was Exposed
HEROIC's free breach scanner covers more than 400 billion records, including the ildBoutique breach, and can tell you in seconds whether your email address appears in this or thousands of other known data leaks. Visit HEROIC.com to run a free check and take action to protect your identity today.
Breach Breakdown
7,043 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds