The SaveCoin Data Breach Means Someone Could Be Logging Into Your Accounts
HEROIC analysts identified the SaveCoin breach while reviewing a collection of US-based financial and coupon platform leaks from August 2018. The SaveCoin platform, which provides deals, coupons, and discounts to American consumers, had 32,269 user records extracted from its database. Exposed data included email addresses and hashed passwords. The breach has since occured in multiple aggregated credential dumps circulating on dark web marketplaces and Telegram channels used by threat actors.
Why Hashed Credentials from a Financial Deals Platform Are High-Value Targets
Users of coupon and deals platforms like SaveCoin frequently register with the same email and password they use on retail shopping sites, banking apps, and loyalty programs. Attackers who obtain these hashes can run them through cracking tools and then test the results across accessable financial services and e-commerce platforms. The overlap between SaveCoin's user base and users of payment-linked platforms makes this breach particularly attractive for fraud operations.
What Was Exposed in the SaveCoin Breach
- Email Address
- Password Hash
The SaveCoin Breach Means Someone Could Already Be Testing Your Login
If your email and password were among the 32,269 records exposed in the SaveCoin breach, automated credential stuffing tools may have already tested that combination against your bank, your Amazon account, and your email provider. Account takeover on a financial or shopping platform can lead directly to unauthorized purchases, identity theft, and credit fraud. Users who reused their SaveCoin password elsewhere and have not changed it since 2018 remain at risk every day this data continues to circulate.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a platform's backend database through techniques such as SQL injection, exploitation of unpatched vulnerabilities, or credential-based admin access. The attacker exports user tables containing emails, passwords, and account data. The extracted records are compressed and transferred off the target server before detection, then sold or shared in dark web forums where other criminals use them for credential stuffing and fraud campaigns.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email address against more than 400 billion records, including the SaveCoin breach dataset. Go to HEROIC.com to run a free scan and find out whether your credentials are already in the hands of attackers before they use them against you.
Breach Breakdown
32,269 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds