The Redem Breach: 23,607 Bcrypt-Hashed Passwords Exposed
HEROIC analysts identified a 2015 breach of Redem, a Nigerian gift card marketplace, that exposed 23,607 accounts. The leaked data includes first and last names, email addresses, usernames, and passwords hashed with bcrypt.
Why the Redem Leak Is Dangerous
Bcrypt is a stronger hashing algorithm than the MD5 or SHA-1 seen in many older breaches, which means these password hashes are harder to crack. Even so, weak or commonly used passwords can still be recovered with enough time and computing power, and the full names paired with emails and usernames make this data useful for identity theft on its own.
What Was Exposed in the Redem Breach
- First and last names
- Email addresses
- Usernames
- Bcrypt password hashes
Why This Matters
Attackers combine names, emails, and usernames from breaches like this one to build convincing phishing messages or to impersonate someone in a fraud attempt. If any of the bcrypt hashes are successfully cracked, that adds credential stuffing to the list of risks, especially for users who reused a weak password across different sites.
How This Database Breach Happened
This incident is classified as a database breach, meaning attackers extracted user records directly from Redem's backend systems. Data from smaller regional marketplaces like this one often stays out of the spotlight for years before resurfacing on data trading channels, which is exactly what happened with this decade-old leak.
Check If You Are Affected
If you ever created an account on Redem, it is worth checking your exposure directly. HEROIC's free breach scanner searches more than 400 billion leaked records, including this breach, so you can find out in seconds.
Breach Breakdown
23,607 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds