The On-Running CN Breach Exposed 214,435 Chinese Shopper Accounts
HEROIC analysts identified a data breach affecting On-Running CN, the official Chinese e-commerce platform for the Swiss athletic footwear brand On-Running, dated August 27, 2024. The breach exposed 214,435 user records pulled directly from the platform's backend database. The compromised data includes phone numbers, usernames, password hashes, email addresses, birthdays, and gender information, pointing to a direct database extraction rather than a surface-level scraping event.
When attackers get access to this combination of data, the risks escalate quickly. Password hashes paired with usernames and email addresses are prime targets for offline cracking attempts. Once a hash is cracked, that credential can be tested against dozens of other platforms, a technique known as credential stuffing. Birthdays and phone numbers layer on the ability to bypass security questions, intercept SMS-based two-factor authentication codes, and execute convincing social engineering attacks.
What Was Exposed
- Phone Number
- Username
- Password Hash
- Email Address
- Birthday
- Gender
Why This Matters
Database breaches from retail platforms are a reliable source of fresh credentials for credential stuffing campaigns. Attackers load leaked username and password hash combinations into automated tools and test them against banking, social media, and e-commerce accounts. Even hashed passwords carry risk if the hashing algorithm is weak or if users have simple passwords. The birthday and gender data fills out identity profiles that can be sold on dark web markets or used to verify identity during account recovery fraud. For Chinese users, where a single phone number is often tied to multiple services including payment apps, the exposure of phone numbers is a particularly serious risk factor.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to an organization's backend data store and extracts records in bulk. This can happen through several routes: exploiting unpatched software vulnerabilities in web applications, using stolen administrative credentials, or taking advantage of misconfigured database servers exposed to the internet. Once inside, the attacker can query and download millions of rows of data quickly and quietly. The breach at On-Running CN reflects this pattern, with structured personal and authentication data extracted in a way that suggests direct database-level access rather than incidental exposure.
Check If You Are Affected
If you have ever created an account on the On-Running CN platform, your data may be part of this breach. HEROIC operates a free breach scanner powered by a database of over 400 billion records. You can search your email address to see whether your information has appeared in this or other known breaches. Changing your On-Running CN password and any accounts where you reused that password is strongly recommended as an immediate precaution.
Breach Breakdown
214,435 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds