Order It On
We noticed a recent resurgence of interest in a dataset originating from April 8th, 2019, making its way through established dark web marketplaces. This particular leak, attributed to the now-defunct U.S. food ordering platform "Order It On," surfaced on a prominent hacking forum. What struck us was not only the age of the data but the persistent utility of plaintext passwords in credential stuffing attacks, even years after the initial compromise. The dataset, impacting 59,982 user accounts, presents a classic example of how seemingly old breaches can continue to fuel ongoing malicious activity.
The breach breakdown reveals a straightforward database exfiltration event. The compromised data primarily consists of email addresses and plaintext passwords, a configuration that immediately flags it for credential stuffing and account takeover (ATO) campaigns. The source structure indicates a direct dump from a user authentication database, likely accessed through a vulnerability or compromised credentials. The leak locations are typical of such incidents, appearing on well-known hacking forums and subsequently being aggregated into larger combolists. The 59,982 records exposed represent a significant pool of potentially compromised credentials, particularly concerning given the platform's former user base.
While this specific breach predates significant public reporting, its characteristics align with numerous similar incidents that have been documented. The persistence of plaintext passwords in such leaks is a recurring theme in cybersecurity research, with reports from organizations like Verizon (Data Breach Investigations Report) consistently highlighting the vulnerability introduced by this practice. The aggregation of such compromised credentials into combolists is a well-documented OSINT and threat intelligence concern, enabling threat actors to systematically target other online services where users may have reused credentials.
We observed a significant data dump appearing on a prominent underground forum on April 8th, 2019, detailing a breach impacting the U.S.-based online food ordering platform, Order It On. This incident, affecting 59,982 users, is notable for the inclusion of plaintext passwords alongside email addresses. The continued availability and potential reuse of this information underscore the enduring threat posed by legacy data breaches. The platform's subsequent defunct status does little to mitigate the risk to individuals whose credentials may have been compromised.
The breach involved a direct database compromise, yielding a dataset containing email addresses and, critically, passwords stored in clear text. This makes the compromised records highly valuable for threat actors engaged in credential stuffing operations. The 59,982 records represent a substantial risk of account takeovers across other services where users may have reused their Order It On credentials. The leak was initially discovered on a prominent hacking forum, a common vector for such data to enter the threat actor ecosystem and be incorporated into larger, more potent combolists.
This type of incident, where plaintext passwords are leaked, is a recurring theme in cybersecurity. While specific news coverage for this particular Order It On breach is limited due to its age and the platform's closure, the broader implications are well-understood. Research from various cybersecurity firms consistently points to the dangers of password reuse and the exploitation of leaked credential pairs. The nature of this leak aligns with typical database breaches that fuel the broader underground economy of compromised account information.
Our analysis flagged a dataset from April 8th, 2019, that has recently been circulating more widely on dark web marketplaces, originating from the now-defunct U.S. online food ordering service, Order It On. What is particularly striking about this incident is the direct exposure of plaintext passwords for nearly 60,000 users. This level of vulnerability, even in a legacy breach, presents an immediate and persistent threat to credential security across the internet. The discovery highlights the long tail of risk associated with poorly secured authentication data.
The breach appears to stem from a direct database compromise, resulting in the exfiltration of 59,982 user records. The compromised data includes email addresses and, most alarmingly, passwords in plaintext. This makes the dataset a prime candidate for credential stuffing attacks, where threat actors systematically attempt to log into other online services using the leaked combinations. The leak was initially observed on a prominent hacking forum, a common distribution point for such compromised data, which is then often integrated into larger combolists for more efficient exploitation.
While specific media reports on this particular Order It On breach are scarce, the scenario is a well-documented phenomenon in cybersecurity. The practice of storing passwords in plaintext is a critical security failure that has been repeatedly warned against by security experts and organizations like NIST. The aggregation of such data into combolists is a known threat vector, enabling widespread account compromise across various online platforms, as evidenced by numerous threat intelligence reports detailing the ongoing exploitation of such datasets.
Breach Breakdown
59,982 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds