Attackers Drained 62,897 Records From Promofit.nl in One Breach
HEROIC discovered 62,897 records in Promofit.nl on 10 January 2025, leaking email addresses, phone numbers, usernames, first and last names, and Argon2 password hashes tied to an eCommerce audience based in the Netherlands. Promofit.nl is a Dutch online store, and attackers walked away with a full customer roster written in Dutch, complete with enough contact detail to build convincing follow-up scams.
Why This Database Breach Is Dangerous for Dutch Shoppers
This breach is dangerous because it pairs real Dutch identities with working mobile numbers and email addresses, a combination attackers prize for localized phishing. The password hashes use Argon2, which is among the strongest algorithms in use today, yet weak or reused passphrases can still be cracked with enough GPU time, and every leaked identity can be matched to accounts on other platforms through credential reuse.
What Was Exposed in Promofit.nl
- Email addresses for 62,897 Dutch eCommerce customers
- Mobile and landline phone numbers
- Full first and last names
- Account usernames tied to Promofit.nl
- Argon2 password hashes ready for offline cracking
- Language and region markers that confirm Netherlands residency
Why This Matters
Contact-rich leaks like Promofit.nl fuel targeted SMS phishing, fake package-delivery scams, and Dutch-language fraud that is far harder for consumers to spot than generic English lures. Once a victim reuses a Promofit.nl password elsewhere, attackers can pivot into banking portals, webmail, and social accounts, turning a single eCommerce breach into a cascade of account takeovers.
How Database Breaches Work
A database breach typically starts with an exposed backup, a stolen admin credential, or an unpatched web application that allows SQL injection. Once inside, attackers export the user table in bulk, then post or sell the dump on forums like BreachForums or within private Telegram groups. From there, the file is scraped, repackaged, and merged into combo lists used for credential-stuffing campaigns months or years after the original intrusion.
Check If You Are Affected
HEROIC scans more than 400 billion compromised records, including the Promofit.nl dataset, so you can see in seconds whether your email, phone number, or password surfaced in this breach. Run a free HEROIC scan to catch exposed credentials before attackers use them, rotate any Promofit.nl password you have reused, and enable multi-factor authentication on any account linked to that email.
Breach Breakdown
62,897 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds