Search Your Email: PharmaCosmetica Exposed 820,459 Accounts
HEROIC analysts discovered a major database breach affecting PharmaCosmetica, a Russian online health and cosmetics retailer, dated August 12, 2024. The incident exposed 820,459 records from the pharmacosmetica.ru platform. The stolen data included email addresses, phone numbers, first names, last names, birthdays, and MD5-hashed passwords — a combination that creates immediate and lasting risk for every person affected.
MD5-hashed passwords are effectively the same as plaintext passwords for any attacker with access to modern cracking hardware. MD5 was deprecated for password storage decades ago; rainbow tables and GPU-accelerated cracking tools can reverse the majority of MD5 hashes in hours or days. Anyone who used PharmaCosmetica with a password they also use elsewhere is at risk of having every one of those accounts compromised, even now. The addition of birthday data makes identity verification bypasses and account recovery attacks significantly easier.
What Was Exposed
- Email addresses
- Phone numbers
- Password hashes (MD5)
- First names
- Last names
- Birthdays
Why This Matters
The scale of 820,459 exposed records — combined with crackable passwords and birthday data — makes this breach a high-value asset for criminal operations. Attackers can perform credential stuffing across banking, email, and social media platforms using the cracked passwords. Birthdays paired with full names and contact details enable identity fraud, fraudulent credit applications, and account recovery attacks on services that use date of birth as a security question. Health-adjacent purchase history, if inferred from the platform type, can also be used in targeted extortion or insurance fraud schemes.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a backend data store by exploiting vulnerabilities such as SQL injection, unpatched software, or stolen administrative credentials. Once inside, the attacker exports the entire user table — in this case, over 820,000 rows — and distributes it on dark web marketplaces. Platforms storing passwords as MD5 hashes provide almost no additional protection once the database is stolen, because the hashes can be cracked offline without any interaction with the live system.
Check If You Are Affected
HEROIC's free scanner checks your email against more than 400 billion exposed records, including the PharmaCosmetica breach. Visit heroic.com to search your email address and find out whether your credentials are circulating on the dark web.
Breach Breakdown
820,459 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds