Breach Intelligence Report 20 Aug 2025

ITConnections Breach Exposes 31,868 UAE eCommerce User Credentials

HEROIC
HEROIC Threat Intelligence Team
Email Address Password Hash
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 31,868
Source Type Database,Combolist
Origin Telegram
Password Type MD5

In August 2018, ITConnections -- a UAE-based eCommerce platform operating at itconnections.me -- suffered a data breach that exposed the account credentials of 31,868 registered users. The compromised data included email addresses and MD5-hashed passwords, a hashing algorithm widely recognized as cryptographically broken and vulnerable to rapid cracking using modern hardware. ITConnections operated as an online marketplace connecting buyers and sellers in the United Arab Emirates, serving a customer base that frequentley conducted financial transactions and stored personal account information on the platform. The exposure of thier login credentials created immediate risk of account takeover, unauthorized purchases, and broader credential stuffing attacks across any other platforms where users had reused the same password.

Why This Is Dangerous

MD5-hashed passwords provide dramatically weaker protection than modern alternatives like bcrypt, Argon2, or SHA-256 with salting. MD5 was deprecated as a password storage mechanism long before 2018, yet ITConnections continued to rely on it. Attackers who obtain an MD5 hash database can crack a large percentage of passwords within hours using GPU-accelerated rainbow table lookups and dictionary attacks. In an eCommerce context, cracked credentials carry particularly serious consequences -- attackers can make unauthorized purchases using saved payment methods, redirect orders, harvest shipping addresses and phone numbers, and use the account to launder fraud. UAE-based eCommerce users who recieve credential theft notices may also face complications in reporting fraud across international payment systems. A single cracked eCommerce account can yield far more than the value of the account itself.

What Was Exposed

  • Email addresses for 31,868 registered ITConnections accounts
  • MD5 password hashes (easily crackable using modern GPU hardware and rainbow tables)
  • Account data associated with UAE-based eCommerce transactions and marketplace activity
  • Potential access to saved shipping addresses, order histories, and profile information

Why This Matters

ECommerce account breaches carry elevated financial risk compared to most other platform types. When attackers crack an eCommerce password, they often gain access to saved payment methods, purchase histories, and personally identifiable information that enables identity fraud. The ITConnections breach matters beyond its immediate scope because UAE-based users may not have recieved timely breach notifications -- particularly since the breach occured in 2018 before many regional data protection frameworks were enforced -- meaning compromised credentials remained active and vulnerable for extended periods. The MD5 hashing failure compounded this: even if users had complex passwords, the weakness of MD5 meant passwords could be recovered and tested against other platforms without delay. Credential stuffing campaigns routinely incorporate eCommerce breach data specifically because these accounts are monetizable with minimal additional effort.

How Database and Combolist Breaches Work

The ITConnections breach followed the standard pattern for eCommerce platform compromises. Attackers identified and exploited a vulnerability in the ITConnections web application -- commonly SQL injection, insecure API endpoints, or unpatched content management system components -- to extract the user database. Once the MD5 password hashes were obtained, offline cracking began immediately using precomputed rainbow tables and dictionary-based attacks tailored to common password patterns. The resulting cleartext passwords were then formatted into a combolist alongside email addresses and distributed across criminal forums, Telegram channels, and dark web marketplaces. These combolists are tested against major email providers, banking platforms, and other eCommerce sites using automated credential stuffing tools that can attempt thousands of logins per second. The ITConnections dataset, while not enormous in size, represents 31,868 unique attack vectors against individuals who likely reused passwords across multiple platforms.

Check If You Are Affected

If you ever created an account on ITConnections at itconnections.me, your email address and password hash were included in this breach. Take the following steps immediately:

  • Change your ITConnections password and update the same password anywhere else you have used it
  • Visit Have I Been Pwned and search your email address to see if it appears in this or other known breach datasets
  • Review any eCommerce accounts for unauthorized orders, saved payment methods, or address changes
  • Enable two-factor authentication (2FA) on all email, banking, and shopping accounts that support it
  • Use a password manager to create and store unique, complex passwords for every platform
  • Contact your bank or payment provider if you notice any suspicious charges tied to accounts that used the same credentials

Breach Breakdown

Domain N/A
Leaked Data Email Address,Password Hash
Password Types MD5
Date Leaked 20 Aug 2025
Check in 5 seconds

31,868 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,538 scanned today
Breach Rank #7,044 by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $230.6K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance