Kladovaya Zdorovya Leak of 100,979 Records Fuels Fraud Risk
HEROIC analysts identified a database breach tied to Kladovaya Zdorovya, a Russian eCommerce platform, with the data shared on a Telegram channel on January 8, 2025. The breach exposed 100,979 records, including email addresses, phone numbers, usernames, first and last names, and password hashes stored with a salt.
Why This Is Dangerous
The passwords here weren't left in plaintext, they were hashed using MD5 with a salt added to each one. That's better than no protection at all, but MD5 is an older, fast hashing algorithm that's well known for being crackable with modern computing power, especially against weaker or commonly used passwords. Combined with real names, phone numbers, and usernames, this dataset gives attackers everything they need to build convincing, personalized attacks against more than 100,000 people.
What Was Exposed
- Email addresses tied to customer accounts
- Phone numbers on file with the platform
- Usernames used to log in
- First and last names of customers
- Password hashes secured with MD5 and a salt
Why This Matters
Once attackers crack even a portion of these salted MD5 hashes, they gain working passwords tied to real names, phone numbers, and email addresses, a combination that dramatically increases the success rate of credential stuffing, account takeover, and targeted phishing. The presence of phone numbers also opens the door to SIM-swapping attempts and convincing phone-based scams, since a caller who already knows your name and account details is far more believable. With more than 100,000 people affected, even a small percentage of cracked passwords translates into a large number of compromised accounts elsewhere.
How Database Breaches Work
A database breach happens when an attacker finds a way past a company's defenses, often through an exploited vulnerability or stolen administrative access, and copies its stored customer records directly. In this case, Kladovaya Zdorovya had taken the step of salting its password hashes, a reasonable security practice, but the choice of MD5 as the underlying algorithm leaves the door open to cracking with modern hardware. Once extracted, the stolen database was distributed through a Telegram channel, a common route for these kinds of leaks to reach criminals looking to buy or download fresh customer data.
Check If You Are Affected
You can check whether your email address appears in this breach or any other using HEROIC's free breach scanner, which searches a database of more than 400 billion leaked and breached records. If you're affected, change your password immediately and avoid reusing it anywhere else, and stay alert for phishing attempts that reference your real name or phone number.
Breach Breakdown
100,979 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds