Novo Dono Breached in 2016. The Leaked Data Just Went Public Again.
HEROIC analysts recieved intelligence about a cluster of aged database dumps circulating in Telegram channels used by cybercriminals to trade verified breach data. One of the datasets traced back to Novo Dono, a Portuguese vehicle shopping platform at novodono.com. The original breach occured on August 1, 2016, exposing 3,853 user records including account credentials protected only by MD5 hashing. The data resurfaced packaged alongside larger breach compilations, giving it renewed visibility and usability in automated attack pipelines.
How MD5 Passwords From Shopping Sites Enable Financial Fraud
MD5 is one of the weakest password hashing methods still found in leaked databases. Passwords hashed with MD5 are accessable to attackers using precomputed hash tables that can match billions of common passwords in seconds. Once cracked, credentials from a vehicle shopping platform like Novo Dono are tested against payment portals, email providers, and online banking platforms, particularly when users share the same password across accounts. The financial transaction history and personal identity details common to vehicle marketplace accounts make these records partcularly attractive for fraud.
What Was Exposed in the Novo Dono Breach
- Usernames
- Email addresses
- MD5-hashed passwords
- Account registration details
Why a Vehicle Marketplace Breach Carries Real Financial Risk
Vehicle marketplace accounts often contain personal contact information, address details, and transaction history tied to high-value purchases. Attackers beleive this data is worth combining with other breach records to build complete identity profiles. Once assembled, those profiles are used in identity theft, financial fraud, and targeted phishing campaigns that impersonate legitimate sellers or buyers. Credential stuffing using the Novo Dono records can also unlock access to email accounts and banking portals where users reused the same seperate password from their marketplace login.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to the server storing a website's user records. For platforms like Novo Dono, this typically involves exploiting a vulnerability in the web application or the underlying database server. The attacker extracts the user table, which contains account information and password hashes, and packages it for sale or sharing in criminal communities. Even when the breach occurred years ago, the extracted data remains valid as long as users have not changed the passwords associated with their exposed email addresses.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches over 400 billion compromised records, including the Novo Dono database leak. Enter your email address to instantly check whether your account was part of this breach or any other known data leak and get guidance on securing your accounts.
Breach Breakdown
3,853 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds