It’s Only Cigars, LLC
We noticed a recent resurfacing of credentials associated with a defunct e-commerce entity, It’s Only Cigars, LLC. This particular dataset, initially leaked in August 2018, has reappeared on a prominent dark web marketplace, indicating a potential for renewed exploitation. What struck us was the continued availability and apparent utility of this older, seemingly low-value data. The breach, affecting 5,048 individuals, comprised email addresses and MD5 password hashes, a combination that, while dated, can still be leveraged in credential stuffing attacks against other platforms. The persistence of such breaches underscores a critical vulnerability in the lifecycle management of user data, even for companies that are no longer operational.
The breach of It’s Only Cigars, LLC, discovered in August 2018, involved a database compromise that exposed 5,048 records. The leaked information consisted of email addresses and MD5 password hashes. This type of data is highly susceptible to credential stuffing attacks, where threat actors use the compromised credentials to attempt logins on other websites and services, assuming users reuse passwords. The source structure of the leak points to a direct database exfiltration, likely due to unpatched vulnerabilities or weak access controls. While the company is now defunct, the data's presence on a hacking forum suggests it was either sold or distributed as part of a larger combolist, making it readily accessible to malicious actors seeking to exploit user credentials across the internet.
While there is no direct news coverage of the original It's Only Cigars, LLC breach, its inclusion in broader discussions of historical data leaks and credential stuffing lists is common. OSINT searches reveal the company operated as a U.S.-based online retailer specializing in cigars and related enthusiast products. The MD5 hashing algorithm used for password storage is now considered cryptographically weak and easily reversible with modern hardware, significantly increasing the risk associated with this breach even years later. Security research consistently highlights the ongoing threat posed by credential stuffing, with reports from organizations like the Identity Theft Resource Center (ITRC) frequently detailing the impact of such attacks stemming from older, forgotten data breaches.
Breach Breakdown
5,048 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds