The Prince Jewellery Breach Put 224,062 Customer Passwords and Personal Records Online
HEROIC analysts found 224,062 customer records from Prince Jewellery, an Indian e-commerce jewelry platform, exposed in a database breach dated August 19, 2024. The compromised data set is broad and detailed, combining full identity information with hashed passwords, making this a high-risk exposure for anyone who held an account on the platform. The data appears to have originated from a direct dump of the customer database and was subsequently circulated on underground forums.
The danger here is the combination of factors working together. A full name, birthday, gender, email address, and phone number together form a near-complete identity profile. Adding a hashed password to that set raises the stakes further, as attackers can attempt to crack the hash offline and then test the recovered credentials against banking, email, and social media platforms. Even a bcrypt hash, considered one of the stronger hashing algorithms, is not immune to cracking if the underlying password is weak or commonly used.
What Was Exposed
- Email Address
- Phone Number
- Password Hash (bcrypt)
- First Name
- Last Name
- Gender
- Birthday
Why This Matters
This breach creates multiple converging risks. Credential stuffing is the most immediate: attackers will attempt to use recovered or partially cracked passwords to log into email accounts, banking portals, and other e-commerce sites. Birthdates and full names are frequently used in identity verification, meaning fraudsters could use this data to impersonate victims when contacting financial institutions or mobile carriers. Phone numbers enable SIM-swapping attacks that defeat SMS-based two-factor authentication. The gender field, while seemingly benign, helps attackers construct more believable social engineering scripts.
Account takeover is the central risk. Once attackers gain access to an email account using a cracked password, they can reset passwords for every other service tied to that address, creating a cascade of compromises from a single breach entry point.
How Database Breaches Work
A database breach occurs when attackers gain unauthorized access to a back-end data store, typically by exploiting SQL injection vulnerabilities, misconfigured database permissions, or compromised administrative credentials. E-commerce platforms are common targets because their customer databases are rich with personal and contact information accumulated over years of transactions. Once an attacker exports the database contents, the data is typically compressed and listed for sale or shared freely on dark web marketplaces. Bcrypt-hashed passwords slow down offline cracking attempts but do not prevent them entirely, particularly for accounts with weak or predictable passwords.
Check If You Are Affected
If you have ever shopped on Prince Jewellery or used your email address on the platform, your data may be among the 224,062 records exposed. HEROIC's free breach scanner checks your email against a database of over 400 billion compromised records. Visit heroic.com to run a free scan and see what protective steps are recommended for your specific exposure.
Breach Breakdown
224,062 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds