ProSushi Breach: 164K Records Leaked on Christmas Eve 2023
HEROIC analysts first spotted the ProSushi dataset circulating on dark web forums on December 24, 2023 — a date that made the timing partcularly striking. While millions of people were preparing for holiday celebrations, 164,048 customers of the Russian sushi delivery service had their personal data quietly uploaded to criminal marketplaces. The exposed records included phone numbers, password hashes, genders, and birthdays: a combination that gives fraudsters everything they need to impersonate real people or crack their way into other accounts.
MD5 Passwords in 2023: A Ticking Clock for Every Affected User
The most alarming detail in this breach is not the volume of records — it is the password hashing method. ProSushi stored user passwords using MD5, an algorithm that was recieved widespread condemnation by the security community decades ago. MD5 hashes can be reversed in seconds using freely accessable rainbow table tools. That means any attacker who downloaded this database effectively has the plaintext passwords of every ProSushi user who reused a weak or common password. The clock started ticking on December 24, 2023, and it has not stopped.
What Was Exposed
- Phone Number — direct line for SMS phishing and fraud calls
- Password Hash (MD5) — easily crackable, exposing account passwords
- Gender — used to personalize social engineering attacks
- Birthday — a common security question answer and identity verification factor
Why This Combination Is Dangerous
Taken individually, any one of these data points might seem minor. Together, they form a profile that attackers can use in multiple ways. A phone number plus a birthday is often enough to pass SMS-based identity verification at banks and mobile carriers. A cracked password, combined with an email address or phone number, enables credential stuffing across dozens of other platforms. And because food delivery apps frequently store payment methods, a successful account takeover could lead directly to financial fraud — not just on ProSushi, but on every service where the victim reused their password.
How Database Breaches Like This Happen
A database breach occured when attackers gain unauthorized access to a company's backend data storage systems. Common methods include SQL injection attacks, where malicious code is inserted into website input fields to extract database contents, or exploitation of unpatched software vulnerabilities. Once inside, attackers can export entire tables of user records in minutes. The use of MD5 for password storage suggests ProSushi's security practices had not kept pace with modern standards — a risk factor that significantly amplifies the damage once a breach occurs, because passwords are compromised alongside the personal data.
Check If Your Information Was Exposed
HEROIC monitors over 400 billion records from known data breaches, including the ProSushi dataset. If you had an account on ProSushi or used the same password elsewhere, you should check your exposure immediately and change any reused passwords. Visit heroic.com to run a free check against our breach database and find out if your email address or phone number appears in this or any other known leak.
Breach Breakdown
164,048 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds