MrRental Hack: 39,632 Plaintext Passwords and Emails Leaked
In May 2019, MrRental, a now-defunct tool and equipment rental provider that once served thousands of customers across North America, suffered a serious data breach that exposed the personal account information of 39,632 users. The breach involved a database compromise combined with combolist exposure, resulting in email addresses and plaintext passwords being leaked to unauthorized parties. For a company trusted with customer accounts and rental transactions, this incident represents a significant failure to protect user data.
Why This Is Dangerous
Plaintext passwords are among the most dangerous types of data to have exposed in a breach. Unlike hashed passwords, plaintext credentials require no cracking or decryption -- they are immediately usable by attackers. Anyone who obtained this data could log into MrRental accounts directly, and more critically, attempt those same username and password combinations against email services, banking portals, and social media platforms. This attack technique, known as credential stuffing, is one of the most common and effective methods used by cybercriminals today. With 39,632 accounts compromised, the downstream impact on affected users could be severe and long-lasting.
What Was Exposed
- Email addresses for 39,632 user accounts
- Plaintext (unencrypted) passwords
- Account registration data tied to equipment rental activity
- Data later circulated as part of a combolist compilation
Why This Matters
MrRental may have ceased operations, but the data leaked from this breach did not disappear when the company shut down. Breached credentials frequently end up in underground marketplaces and combolist repositories where they are traded, sold, and used for years after the original incident. Many of the affected users almost certainly recieve phishing emails or find thier accounts accessed without authorization long after forgetting they ever had an MrRental account. The combination of a defunct company and exposed plaintext passwords creates a particularly dangerous situation -- there is no company left to notify users, reset passwords, or provide remediation support.
How Database and Combolist Breaches Work
A database breach typically occured when attackers exploited vulnerabilities in a web application, server misconfiguration, or weak authentication to gain unauthorized access to a backend database. In MrRental's case, the breach involved both a direct database compromise and subsequent combolist exposure. Once attackers extracted the database, they compiled the email and password pairs into a combolist -- a structured file format used to run automated login attempts across hundreds of websites simultaneously. Combolists from events like this one are frequentley packaged with data from other breaches, creating massive credential repositories that circulate in cybercriminal communities for years.
Check If You Are Affected
If you ever created an account on MrRental's website, your email address and password may be part of this breach. You should take action immediately regardless of how long ago you registered:
- Search for your email address in HEROIC's breach database to see if your credentials were exposed
- Change the password you used for MrRental on every other site where you used the same password
- Enable two-factor authentication on your email account and any other critical services
- Monitor your email and financial accounts for unusual activity or unauthorized logins
- Consider using a password manager to generate and store unique passwords for every account
- Be alert to phishing emails that reference rental services, equipment companies, or past account activity
HEROIC's identity monitoring tools can alert you in real time if your data appears in future breaches. Signing up for breach alerts is one of the most effective steps you can take to stay ahead of credential theft and protect your online accounts from compromise.
Breach Breakdown
39,632 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds