How the Loot100 Database Breach Led to 59,743 Stolen Credentials
HEROIC analysts discovered the Loot100 breach while monitoring underground forums and breach aggregation sites for newly surfaced credential dumps. The breach occured in August 2018 and exposed 59,743 user records from Loot100, a quiz-based e-commerce and voucher platform operated by SWAAS Entertainment LLP in New Delhi, India. The exposed data included email addresses and MD5 password hashes, a particularly weak form of password protection that makes these credentials highly accessable to attackers with basic cracking tools.
Why MD5 Password Hashes Put Loot100 Users at Serious Risk
MD5 is a hashing algorithm that was widely used in the early days of the web but has been considered broken for over a decade. When attackers get a database full of MD5 hashes, they can run those hashes through precomputed tables called rainbow tables and recover the original passwords in seconds. Those recovered passwords are then used in automated login attempts across dozens of other sites to find accounts where the same password was reused.
What Was Exposed in the Loot100 Breach
- Email Address
- Password Hash (MD5)
Why the Loot100 Breach Is Still a Threat Years Later
The Loot100 platform may be gone, but the data from this breach continues to circulate in credential markets and forum dumps. Attackers use this type of data in credential stuffing attacks, trying leaked logins against email providers, banks, and shopping platforms. Users who seperate their passwords for every service are protected, but anyone who reused their Loot100 credentials elsewhere remains at risk of account takeover and identity theft even today.
How Database Breaches Work
A database breach happens when an attacker finds a way into a company's backend systems, whether through a software vulnerability, a stolen admin password, or a misconfigured server. Once inside, they copy the user database and take it with them. That file, containing email addresses and hashed passwords, is then sold or posted online, where other criminals use it to attempt logins across the internet at massive scale.
Check If Your Data Was Exposed
HEROIC offers a free breach scanner that checks your email against more than 400 billion leaked records, including the Loot100 breach. Run a free scan at HEROIC.com right now to see whether your information is already in the hands of attackers and get guidance on what to do next.
Breach Breakdown
59,743 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds