If You Reuse Passwords, the Made to Sell Breach Should Worry You
HEROIC analysts identified a database breach tied to Made to Sell, an Italian retail consultancy, when records surfaced on underground forums in June 2023. The exposed dataset contained approximately 6,617 records with personal details recieved directly from their customer database. If you shop at Italian online retailers or reuse passwords across accounts, this breach should be on your radar.
Your Hashed Password May Already Be Cracked
Attackers who got ahold of this data didn't just grab names and emails. They walked away with SHA1 and bcrypt password hashes. SHA1 in particular is notoriously weak and cracks fast with modern GPU rigs. If your password from Made to Sell was simple or common, there is a real chance it has already been reversed. That cracked password then gets fed into credential stuffing tools that hit your email, your bank, your Netflix, and anything else where you used the same login.
What Was Exposed in the Made to Sell Breach
- Email addresses
- Phone numbers
- First and last names
- Gender
- Birthday
- Password hashes (SHA1 and bcrypt)
Why a Retail Consultancy Breach Hits Harder Than You Think
Made to Sell operates in the global retail consultancy space, which means their customer base spans multiple countries. When that kind of cross-border data gets exposed, it becomes a goldmine for identity thieves and phishing crews. Your name, birthday, and phone number together are enough to impersonate you in a SIM swap attack. Add a cracked password hash and attackers have everything they need for full account takeover. The fraud risk here is not hypothetical, it is very much accessable to anyone who downloaded this dump.
How a Database Breach Works
A database breach occured when an unauthorized party gains access to a company's backend data storage, usually through a vulnerability in their web application, a misconfigured server, or compromised admin credentials. Once inside, the attacker can export entire tables of user records in minutes. The data is then compressed, posted to dark web forums, or sold privately. Companies often don't detect this for weeks or months, meaning your data could have been circulating long before any public disclosure.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches over 400 billion compromised records to tell you exactly what information of yours is out there. Don't wait for a company to notify you. Run your email through the scanner now and see if the Made to Sell breach or any other leak has put your personal data at risk.
Breach Breakdown
6,617 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds