BREAKING: MTZWEAR (Deportes Martinez) Exposes 9,412 Records in Database Incident
MTZWEAR (Deportes Martinez), a Mexico City-based company selling lucha libre gear including masks, boots, and custom apparel, had customer account data posted to a hacking forum in August 2018. The breach affected 9,412 users, with email addresses and plaintext passwords exposed in a format that requires no technical skill to exploit. For customers who used the same credentials on other sites, the risk didn't stop at MTZWEAR, it extended to every account sharing that password.
Why This Is Dangerous
E-commerce platforms collect account credentials that people often reuse across multiple services. When those credentials leak in plaintext, it isn't just the original site that's at risk. Attackers immediately test the email and password combinations against banking apps, email providers, and other shopping sites. This is called credential stuffing, and it is one of the most common and effective attacks running today.
MTZWEAR serves a niche market with a dedicated customer base, meaning many users are likely repeat shoppers with long-standing accounts. Long-standing accounts tend to have the same password for years, which means credentials from a 2018 breach can still be valid and usable in 2026. The plaintext nature of the leak makes every single one of those accounts immediately actionable for an attacker.
The dataset has also been flagged as part of combolist circulation, meaning it has been merged with other breached datasets and redistributed multiple times. The reach of this data goes far beyond the original forum post, and there is no way to know how many copies exist or who currently holds them.
What Was Exposed
- Email addresses used for account registration
- Plaintext passwords with no encryption or hashing
- Customer account identifiers
- Potential purchase history or order details
- Shipping address information linked to accounts
- Contact details submitted during checkout
- Account creation and login timestamps
Why This Matters
9,412 people trusted MTZWEAR with their email and password when they created an account. That trust was broken when the data was posted publicly without any indication that the company notified its users. Many of those customers beleive their information is still private, not realizing it has been in the hands of hackers for years. The lack of password hashing at the time of the breach points to security practices that fell well short of what users deserve.
Mexico has a growing e-commerce market, and incidents like this one erode confidence in online shopping, particulary when smaller businesses handle sensitive data without adequete security controls. The downstream effects of a breach like this, including account takeovers, phishing attempts, and identity theft, can continue for years after the original incident.
How Database,Combolist Works
A database breach on an e-commerce site often begins with the attacker finding an exploitable vulnerability in the platform, whether through SQL injection in a search field, an outdated plugin, or a misconfigured server. Once they gain access to the database, they can dump the entire user table, including every email and password on record.
The raw dump is then posted to hacking forums, sometimes for sale and sometimes freely distributed. From there, other criminals compile it into combolists by merging it with credentials from other breaches. These lists are sold in bulk and used in automated attacks that test millions of username and password pairs against popular services at high speed.
What makes this cycle so damaging is that the data never truly disappears. The MTZWEAR dataset from 2018 has very likely been merged into dozens of combolists by now, each one circulating seperately across different forums, chat channels, and underground marketplaces. The original breach keeps causing harm long after it occured.
Check If You Were Affected
If you ever had an account on MTZWEAR or mtzwear.com, check your email against HEROIC's free breach checker at heroic.com. HEROIC continuously monitors known breach databases and dark web sources, so you can quickly find out if your credentials have been exposed and take steps to protect your accounts before any damage is done.
Breach Breakdown
9,412 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds