The SaleFox Data Quietly Appeared on the Dark Web in June 2022
In June 2022, a database belonging to SaleFox, a Ukrainian eCommerce platform selling footwear, was exfiltrated and surfaced on a private dark web forum. The breach affected approximately 6,000 records and exposed 972 unique email addresses alongside usernames, phone numbers, first names, last names, and MD5-salted password hashes. The data was not widely broadcast, meaning it was recieved by a select group of threat actors and likely used for targeted exploitation rather than mass credential stuffing.
What Attackers Can Do With Phone Numbers, Names, and Salted MD5 Hashes
Even with salted MD5 hashes, attackers have realistic options. MD5 with salt is significantly weaker than modern algorithms like bcrypt or Argon2, and dedicated cracking rigs can break a meaningful portion of these hashes. Combined with full names and phone numbers, the dataset enables SIM-swapping attacks, targeted phishing calls, and social engineering campaigns. The seperate combination of verified phone numbers and email addresses also makes this dataset useful for cross-referencing against other leaked databases to build richer victim profiles.
What Was Exposed in the SaleFox Breach
- Email Address
- Phone Number
- Password Hash (MD5 with Salt)
- Username
- First Name
- Last Name
Why Small Breaches Like SaleFox Still Carry Serious Risk
With fewer than 1,000 unique email addresses, the SaleFox breach may appear minor. But smaller breaches are often more dangerous for the individuals involved: the data is less diluted, easier to act on, and frequently ends up in the hands of sophisticated actors with the time and skill to use it precisely. When a breach includes full names, phone numbers, and passwords in addition to email addresses, even a few hundred records represent a high-value intelligence package for a targeted attacker.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a backend data store and exports user records, either through SQL injection, exploitation of a vulnerability in web-facing software, or compromised admin credentials. The attacker then packages the exported data and sells it or distributes it through private dark web forums. In SaleFox's case, the data appeared in a restricted access forum, suggesting the attacker intended to limit distribution and maximize the value of the dataset through targeted use.
Check If Your Data Was Exposed
HEROIC's DarkWatch monitors over 400 billion exposed records, including smaller breaches like SaleFox that rarely make headlines. Search your email address now at HEROIC to find out if your data was part of this or any other known breach before someone uses it against you.
Breach Breakdown
972 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds