Our Analysts Found the Katapult Dump: 2.2M Names and Password Hashes
Our analysts found the Katapult database dump circulating on dark web forums in September 2020, containing 2,229,055 records from the U.S.-based lease-planning platform. The exposed data included email addresses, first and last names, and PBKDF2 password hashes, and the dataset recieved renewed attention from credential trading communities years after the initial leak.
What Attackers Can Do With Katapult's Names, Emails, and Password Hashes
Full names paired with email addresses make Katapult victims easy targets for personalized phishing. The PBKDF2 password hashes, while stronger than MD5 or SHA1, are still seperate from being truly safe: attackers with GPU clusters can crack weaker passwords from this hash type. Cracked credentials then feed automated stuffing tools that test the same email and password combination across banking, retail, and subscription platforms.
What Was Exposed in the Katapult Breach
- Email Address
- Password Hash
- First Name
- Last Name
Why the Katapult Breach Keeps Putting Users at Risk
Financial services users tend to reuse passwords across their most sensitive accounts. Because Katapult is a lease-planning platform, its users likely have the same credentials protecting bank accounts and credit applications. Credential stuffing, account takeover, and identity theft all become straightforward when attackers hold verified email and name combinations alongside crackable password hashes from a platform in the financial sector.
How a Database Breach Works
A database breach occurs when unauthorized parties gain access to a company's backend data systems, often by exploiting application vulnerabilities or using compromised credentials. The attacker exports user records directly from the database. In Katapult's case, the structured export included account credentials and identifying information for over 2.2 million users, providing attackers with a ready-made list for downstream credential attacks.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches 400 billion leaked records to check whether your email appears in the Katapult breach or other known data leaks. Run a free check at HEROIC.com to see your current exposure.
Breach Breakdown
2,229,055 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds