The In Corio Breach Gave Hackers Passwords and Birthdates for 20K Accounts
HEROIC analysts recieved data indicating a significant breach affecting In Corio, a French e-commerce platform. The incident was confirmed on November 16, 2022, and involved the exposure of 20,152 records. The leaked dataset contained a combination of personal identifiers and bcrypt-hashed passwords, a pairing that signals a direct compromise of the platform's user database and raises serious concerns about credential reuse across other platforms.
bcrypt Passwords Plus Personal Data: What Attackers Can Do
While bcrypt is a stronger hashing algorithm than MD5, it is not uncrackable. Attackers who acquire bcrypt hashes alongside email addresses, usernames, full names, IP addresses, and birthdays have everything they need to prioritize cracking efforts against high-value targets. If the implementation used weak salts or low cost factors, the hashes become accessable to offline cracking rigs. Combined with birth dates and names, attackers can also attempt to bypass account recovery flows on other services entirely, without needing to crack the password at all.
What Was Exposed in the In Corio Breach
- Email Address
- Password Hash (bcrypt)
- Username
- First Name
- Last Name
- IP Address
- Birthday
Why French eCommerce Breaches Put Consumers at Risk
French e-commerce customers who used the same email and password combination on In Corio as they do on banking, social media, or other retail platforms are partcularly exposed. Birthday and full name data makes identity verification bypass straightforward for a determined attacker. Credential stuffing tools can cycle through thousands of login attempts per minute, turning one breached account into a key that unlocks many others across the web.
How a Database Breach Works
A database breach occurs when an attacker bypasses a platform's access controls and extracts data directly from the backend database. Common entry points include SQL injection vulnerabilities, stolen admin credentials, or improperly secured database endpoints. Once inside, the attacker can export entire user tables in a single query. The resulting dump contains every stored field for every user, exactly the kind of structured data seen in this In Corio incident.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion indexed records to detect whether your email address appears in the In Corio breach or any other known incident. Run a free check at HEROIC.com before attackers use your data against you.
Breach Breakdown
20,152 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds