Marketplace Buyers Exposed: LiveAuctioneers Breach Leaked 3.4M Records
HEROIC analysts identified the LiveAuctioneers breach, which occured in June 2020 and exposed 3,382,641 records from the online antiques and collectibles marketplace. The leaked data includes email addresses, first and last names, IP addresses, phone numbers, and MD5 password hashes. The breach was subsequently sold and distributed across hacking communities, and the data remains accessable in underground markets where it continues to fuel credential stuffing campaigns.
How Full PII and Cracked Passwords Enable Identity Theft and Account Takeover
The combination of full names, phone numbers, IP addresses, and email addresses alongside crackable MD5 password hashes gives attackers everything they need to impersonate victims. Unsalted MD5 hashes can be reversed quickly using rainbow tables, exposing the original password. Attackers then use those credentials against email providers, financial platforms, and e-commerce sites. The PII elements are partcularly useful for bypassing identity verification challenges and crafting convincing phishing messages targeting LiveAuctioneers customers.
What Was Exposed in the LiveAuctioneers Breach
- Email Address
- First Name
- Last Name
- IP Address
- Phone Number
- Password Hash
Why Marketplace Customers Face Elevated Fraud Risk After This Breach
Online marketplace users often store payment methods and shipping addresses on their accounts, making them high-value targets after a breach. The LiveAuctioneers incident exposed over 3.3 million records from buyers and sellers of antiques and collectibles, a demographic that may beleive niche platforms are safer than major retailers. The recieved wisdom that smaller marketplaces fly under the radar of attackers is directly contradicted by the active trading of this data on hacking forums for years after the initial breach.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a stored collection of user records, often by exploiting web application vulnerabilities, conducting SQL injection attacks, or using compromised credentials. The attacker extracts the database and typically sells it on hacking forums or dark web markets. In the LiveAuctioneers breach, the extracted records were sold online and widely distributed within hacking communities, where they continue to circulate as part of credential stuffing toolkits.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across 400 billion leaked records to show you exactly what personal data is circulating from your accounts. Search your email at HEROIC now to find out if your LiveAuctioneers information or credentials from any other breach are exposed.
Breach Breakdown
3,382,641 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds