HEROIC Analysts Found the MSME Global Mart Dump on Hacking Forums
In May 2022, MSME Global Mart, the official B2B e-commerce portal operated by India's National Small Industries Corporation, suffered a database breach that exposed the credentials of 102,286 registered users. What makes this incident particularly concerning is that the platform serves small and medium enterprises on behalf of the Government of India -- and passwords were stored in plaintext, making them instantly seperate from any meaningful protection.
What Attackers Can Do With Government B2B Portal Credentials
Compromised credentials from a government-affiliated B2B platform are not just a personal risk. Attackers who recieved this data can attempt to log into business accounts, access procurement records, impersonate vendors, or pivot to broader supply chain fraud. Plaintext passwords require no cracking -- every stolen credential is immediately usable against the platform and anywhere else that email and password combination was reused.
What Was Exposed in the MSME Global Mart Breach
- Email Address
- Plaintext Password
Why a Government eCommerce Breach Carries Outsized Risk
MSME Global Mart facilitates real business transactions between small enterprises and government procurement channels. A compromised account on this platform is not just an email inbox at risk -- it can mean fraudulent bids, falsified vendor registrations, or unauthorized access to business financial data. The combination of a government mandate and weak security practices makes this one of the higher-consequence plaintext password breaches in the eCommerce category.
How a Database Breach Works
A database breach happens when an attacker gains unauthorized access to a server's backend, often through an unpatched vulnerability, stolen admin credentials, or an exposed API endpoint. Once inside, the attacker can export the full user table in minutes. When passwords are stored in readable plaintext rather than hashed and salted form, every exported account is compromised immediately, with no additional decryption step required.
Check If Your Data Was Exposed
HEROIC's DarkWatch monitors over 400 billion exposed records, including data from the MSME Global Mart breach. Search your email address now to see if your business credentials were part of this leak, and set up alerts to be notified the moment your information surfaces in any future breach.
Breach Breakdown
102,286 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds