100K Macquarie Database Breach: How Records Were Stolen
HEROIC analysts identified the Macquarie breach while scanning dark web forums for resurfaced credential dumps in August 2018. The breach occurred at Macquarie, a now-defunct U.S.-based commercial and sales website, exposing 100,482 user records. The compromised data included email addresses and password hashes stored in an unknown format. Researchers believe the dataset has continued to circulate in underground communities years after the original incident, making it an ongoing risk for anyone who used this platform.
How Exposed Email and Password Hashes Put You at Risk
When attackers get hold of email addresses paired with password hashes, their first move is to run cracking tools against those hashes to recover the original passwords. Even hashed passwords can be reversed using widely available software. Once cracked, those credentials become a master key. Attackers try them on Gmail, banking apps, social media, and shopping sites, knowing that many people reuse the same password across multiple accounts. The data from this breach is particularly dangerous because it pairs login credentials that may still work on other platforms today.
What Was Exposed in the Macquarie Breach
- Email Address
- Password Hash
Why the Macquarie Breach Still Matters Today
A breach from 2018 might seem like old news, but the risks are very real right now. Credential stuffing attacks use automated tools to test leaked username and password combinations against dozens of websites simultaneously. If your Macquarie password was reused anywhere, attackers can take over those accounts without you knowing. This kind of attack fuels identity theft, financial fraud, and unauthorized access to private accounts. Older breaches are recycled by criminal marketplaces regularly and re-sold to new buyers who launch fresh waves of attacks.
How a Database Breach Works
A database breach happens when an unauthorized person gains access to the backend storage system of a website or app. Websites store user information like email addresses and passwords in databases so the site can recognize you when you log in. When attackers break into a database, they can copy all of that stored information and walk away with thousands or millions of records in minutes. The stolen data is then sold on dark web marketplaces or used directly to break into other accounts. Many database breaches go undetected for months or even years.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches through more than 400 billion records to tell you if your email address or passwords have appeared in known data breaches including this one. Run a free scan at HEROIC.com to find out if your information was part of the Macquarie breach or any other incident, and get clear steps on what to do next to protect your accounts.
Breach Breakdown
100,482 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds