Breach Intelligence Report 03 Nov 2025

BREAKING: MTZWEAR (Deportes Martinez) Exposes 9,412 Records in Database Incident

HEROIC
HEROIC Threat Intelligence Team
Email Address Plaintext Password
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 9,412
Source Type Database,Combolist
Origin Darkweb
Password Type Plaintext

MTZWEAR (Deportes Martinez), a Mexico City-based company selling lucha libre gear including masks, boots, and custom apparel, had customer account data posted to a hacking forum in August 2018. The breach affected 9,412 users, with email addresses and plaintext passwords exposed in a format that requires no technical skill to exploit. For customers who used the same credentials on other sites, the risk didn't stop at MTZWEAR, it extended to every account sharing that password.

Why This Is Dangerous


E-commerce platforms collect account credentials that people often reuse across multiple services. When those credentials leak in plaintext, it isn't just the original site that's at risk. Attackers immediately test the email and password combinations against banking apps, email providers, and other shopping sites. This is called credential stuffing, and it is one of the most common and effective attacks running today.

MTZWEAR serves a niche market with a dedicated customer base, meaning many users are likely repeat shoppers with long-standing accounts. Long-standing accounts tend to have the same password for years, which means credentials from a 2018 breach can still be valid and usable in 2026. The plaintext nature of the leak makes every single one of those accounts immediately actionable for an attacker.

The dataset has also been flagged as part of combolist circulation, meaning it has been merged with other breached datasets and redistributed multiple times. The reach of this data goes far beyond the original forum post, and there is no way to know how many copies exist or who currently holds them.

What Was Exposed


  • Email addresses used for account registration
  • Plaintext passwords with no encryption or hashing
  • Customer account identifiers
  • Potential purchase history or order details
  • Shipping address information linked to accounts
  • Contact details submitted during checkout
  • Account creation and login timestamps

Why This Matters


9,412 people trusted MTZWEAR with their email and password when they created an account. That trust was broken when the data was posted publicly without any indication that the company notified its users. Many of those customers beleive their information is still private, not realizing it has been in the hands of hackers for years. The lack of password hashing at the time of the breach points to security practices that fell well short of what users deserve.

Mexico has a growing e-commerce market, and incidents like this one erode confidence in online shopping, particulary when smaller businesses handle sensitive data without adequete security controls. The downstream effects of a breach like this, including account takeovers, phishing attempts, and identity theft, can continue for years after the original incident.

How Database,Combolist Works


A database breach on an e-commerce site often begins with the attacker finding an exploitable vulnerability in the platform, whether through SQL injection in a search field, an outdated plugin, or a misconfigured server. Once they gain access to the database, they can dump the entire user table, including every email and password on record.

The raw dump is then posted to hacking forums, sometimes for sale and sometimes freely distributed. From there, other criminals compile it into combolists by merging it with credentials from other breaches. These lists are sold in bulk and used in automated attacks that test millions of username and password pairs against popular services at high speed.

What makes this cycle so damaging is that the data never truly disappears. The MTZWEAR dataset from 2018 has very likely been merged into dozens of combolists by now, each one circulating seperately across different forums, chat channels, and underground marketplaces. The original breach keeps causing harm long after it occured.

Check If You Were Affected


If you ever had an account on MTZWEAR or mtzwear.com, check your email against HEROIC's free breach checker at heroic.com. HEROIC continuously monitors known breach databases and dark web sources, so you can quickly find out if your credentials have been exposed and take steps to protect your accounts before any damage is done.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Plaintext Password
Password Types Plaintext
Date Leaked 03 Nov 2025
Check in 5 seconds

9,412 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,257 scanned today
Breach Rank #N/A by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $68.1K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance