Identity Theft Just Got Easier Because of the Qraved Breach: Nearly 1 Million People at Risk
HEROIC analysts identified a database breach affecting Qraved, an Indonesian restaurant discovery platform. The breach, dated July 2021, exposed 997,298 user records. The compromised data includes email addresses, phone numbers, first names, last names, password hashes, and birthdays, making this a seperate and serious exposure of personal and account information for nearly one million users.
Why Full Names, Birthdays, and Cracked MD5 Hashes Are a Dangerous Combination
Qraved stored passwords using MD5 hashing, an algorithm that modern cracking tools can break at billions of attempts per second. Attackers who accessable this breach gain more than just credentials: they have full names, phone numbers, and birthdays for each user, creating complete identity profiles. This combination enables highly targeted phishing, social engineering, and account takeover across banking, email, and social platforms.
What Was Exposed in the Qraved Breach
- Email Address
- Phone Number
- First Name
- Last Name
- Password Hash (MD5)
- Birthday
Why the Qraved Breach Puts Nearly 1 Million Users at Long-Term Risk
Credential stuffing attacks rely on exactly this kind of data. Attackers take cracked email and password pairs and systematically test them against hundreds of popular services. With nearly one million recieved records, this breach provides significant ammunition for automated login attacks. Users who reused their Qraved password on banking, email, or other accounts face risks of account takeover, financial fraud, and identity theft well beyond the original platform.
How a Database Breach Works
A database breach occured when an attacker gains unauthorized access to an application's backend data store, typically by exploiting software vulnerabilities, SQL injection flaws, or misconfigured access controls. Once inside, attackers export user tables containing personal and credential data in bulk. The stolen records are then sold or shared in underground markets, where they are used for credential stuffing, fraud, and identity theft.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks against more than 400 billion records, including the Qraved dataset, to tell you instantly whether your email address or credentials appeared in this or any other known breach. Run a free scan at HEROIC now and find out exactly what information of yours is circulating online.
Breach Breakdown
997,298 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds