Online Shoppers Targeted in the 319K Record Poshmark Breach
HEROIC analysts identified the Poshmark breach while monitoring credential datasets circulating on dark web forums and private Telegram channels. In May 2018, social commerce marketplace Poshmark suffered a database breach that occured without public disclosure for over a year. The exposed records included email addresses, usernames, and bcrypt password hashes. While 319,025 records appeared in the subset analyzed by our team, the broader breach is beleived to have affected tens of millions of accounts. Poshmark's use of bcrypt hashing provides some protection, but older or weaker passwords remain vulnerable to modern cracking techniques.
Why Fashion Resellers and Online Shoppers Are Prime Targets in the Poshmark Breach
Poshmark users tend to be active online shoppers who also sell items through the platform, often linking payment methods and personal information to their accounts. Attackers who obtain Poshmark credentials can attempt to access the same email and password combination on PayPal, Venmo, banking apps, and other e-commerce platforms. Even bcrypt-hashed passwords can be cracked if the original password was short or simple. Once inside a linked payment account, attackers can drain balances, make unauthorized purchases, or redirect earnings. Poshmark users who reuse passwords across other shopping or financial sites are partcularly at risk from this exposure.
What Was Exposed in the Poshmark Breach
- Email Address
- Username
- Password Hash (bcrypt)
Why Online Shoppers Should Act on Old Breach Data Now
Many people assume that a breach from years ago no longer poses a risk, especially if they have not noticed anything unusual with their accounts. In reality, attackers stockpile breach data and deploy it in waves, often waiting until the data appears in larger combined datasets or until a target platform becomes more valuable. Credential stuffing attacks are automated and can test millions of login combinations per hour. Account takeovers can lead to financial fraud, identity theft, and unauthorized access to linked services like shipping accounts, email inboxes, and marketplace payment systems. Anyone who used Poshmark in 2018 and has not changed their password since should treat their credentials as seperate from anything they would consider safe today.
How a Database Breach Works
A database breach happens when an attacker gains unauthorized access to the systems where a company stores its user records. This can happen through exploited software vulnerabilities, phishing attacks against employees with admin access, or weaknesses in how a company's servers are configured. Once inside, attackers copy the database quietly, often avoiding detection for months. In Poshmark's case, the breach happened in 2018 but was not disclosed until 2019, meaning users had no way to protect themselves in the meantime. The stolen records then circulate through private and public channels, giving attackers ongoing opportunities to exploit the data long after the original incident.
Check If Your Data Was Exposed
HEROIC provides a free breach scanner powered by a database of over 400 billion compromised records. If your email address was part of the Poshmark breach or any other incident, you can check in seconds. Visit the HEROIC breach scanner today to see your exposure and take steps to protect your accounts and financial information before attackers get there first.
Breach Breakdown
319,025 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds