JennyHaskins Data Breach Exposes 39,099 eCommerce Customer Accounts
HEROIC's DarkHive intelligence system discovered the JennyHaskins data breach, exposing 39,099 records in August 2018. JennyHaskins is a U.S.-based eCommerce platform specializing in craft, quilting, and sewing products, serving a dedicated community of craft enthusiasts and hobbyists. The compromised data included email addresses and SHA1 password hashes, putting registered customers at risk of credential-based attacks.
Why This Is Dangerous
eCommerce platforms store customer account information that may include saved shipping addresses, order histories, and stored payment method references, making them attractive targets for credential theft. SHA1 password hashes are considered cryptographically weak and can be cracked using modern tools and rainbow tables, effectively exposing the underlying plaintext passwords. Customers who reused their JennyHaskins credentials on other shopping sites, email accounts, or banking platforms face cascading account compromise risks from this breach.
What Was Exposed
- Email Address
- Password Hash (SHA1)
Why This Matters
With nearly 40,000 records exposed, the JennyHaskins breach provides attackers with a dataset of craft and sewing community shoppers whose credentials can be tested against major retail platforms, Amazon, PayPal, and email providers. eCommerce account takeovers can result in unauthorized purchases, theft of loyalty points and gift card balances, and access to stored payment method information. The breach also enables highly targeted phishing campaigns tailored to craft and sewing product interests.
How Database Breaches Work
A database breach occurs when attackers exploit security vulnerabilities in eCommerce platform code, server configurations, or third-party plugins to gain unauthorized access to stored customer data. Online shops frequently use content management systems with plugins for shopping cart functionality that may contain known security vulnerabilities if not regularly updated. SHA1 is an outdated hashing algorithm that provides inadequate protection for passwords in a modern threat environment. Once attackers access the database, they export customer credential data and circulate it through underground markets.
Check If You Are Affected
HEROIC offers a free identity scanner searching over 400 billion records including data from the JennyHaskins breach. Visit heroic.com to check if your information was exposed.
Breach Breakdown
39,099 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds