Inside the Brelect Leak: 2,782 phpBB and bcrypt Hashes Exposed
HEROIC analysts identified a dataset tied to Brelect, a French eCommerce platform, circulating on a hacking forum. The breach dates back to August 26, 2018, and exposed 2,782 records made up of email addresses paired with password hashes.
Why This Is Dangerous
What makes this leak interesting is the mix of hashing methods used to store the passwords: some with the older phpBB3 format built on MD5, and others with bcrypt, a much stronger, modern algorithm. That split matters because the phpBB3-hashed passwords are far easier for an attacker to crack than the bcrypt ones, meaning some Brelect users face a real, near-term risk while others have meaningfully better protection built into how their password was stored.
What Was Exposed
- Email addresses of Brelect customers
- Password hashes, stored using a mix of phpBB3 (MD5-based) and bcrypt hashing
Why This Matters
Every password cracked from this leak becomes a candidate for testing against other accounts the same person owns. Because people frequently reuse passwords across shopping sites, email, and banking, even a leak limited to under 3,000 records can lead to credential stuffing and account takeover well beyond Brelect itself. From there, the risk extends to identity theft and financial fraud, particularly for anyone whose password fell into the weaker, easier-to-crack phpBB3 group.
How Database and Combolist Breaches Work
This breach started with a direct compromise of Brelect's database, where an attacker extracted stored customer records straight from the platform. The mixed hashing methods suggest Brelect may have upgraded its password security at some point, hashing newer passwords with bcrypt while older ones remained on the weaker phpBB3 system, both of which were exposed together in the same breach. Once posted to a hacking forum, this kind of data typically gets merged with records from unrelated breaches into combolists, large combined files that let attackers automate login attempts across many different websites at once.
Check If You Are Affected
You can check whether your email address appears in this breach or any other using HEROIC's free breach scanner, which searches a database of more than 400 billion leaked and breached records. If you're affected, change that password anywhere you may have reused it, regardless of which hashing method protected it originally.
Breach Breakdown
2,782 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds