Researchers Find the Scrubser Breach Exposed 5,033 Accounts With Hashed Passwords
HEROIC analysts identified a database breach affecting Scrubser, a Saudi Arabian medical online shopping platform operating at scrubser-shop.com. The breach was recorded on July 18, 2024, and exposed 5,033 user records containing email addresses, usernames, password hashes, first names, and last names. The data was extracted directly from the platform's user database and subsequently distributed on a public forum.
With email addresses, usernames, and password hashes all in a single dataset, attackers can run offline cracking operations against the hashed passwords using dictionary attacks and brute-force tools. Once a password is cracked, the attacker has direct login access to the Scrubser account and can attempt to use the same credentials on other platforms the victim uses. The combination of full name with email and username creates a profile complete enough to support targeted phishing, identity theft, and account takeover across multiple services.
What Was Exposed
- Email Address
- Username
- Password Hash
- First Name
- Last Name
Why This Matters
Password hashes, especially those produced by weak or unsalted algorithms, can be reversed through cracking tools to recover the original plaintext password. Once cracked, those passwords fuel credential stuffing campaigns targeting email providers, banking portals, and any other service where the victim reused that password. Full names paired with email addresses create identity profiles that enable convincing phishing emails, fraud applications, and account recovery exploits. For a medical shopping platform, the existence of the account itself may reveal sensitive health-related purchasing habits that can be used for targeted extortion or manipulation.
How Database Breaches Work
Database breaches against e-commerce platforms typically occur when an attacker identifies and exploits a vulnerability in the web application layer, such as SQL injection, insecure API endpoints, or compromised administrative credentials. Once inside, the attacker can query or export the user registration database, which stores account details entered during checkout or account creation. The exported data is then packaged and posted to underground forums or sold to other threat actors. E-commerce platforms in emerging markets sometimes deploy older or misconfigured database software, increasing exposure to known attack techniques.
Check If You Are Affected
HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including e-commerce platform breaches like the Scrubser incident. Run a free scan at heroic.com to find out whether your account credentials or personal information appeared in this breach or any related dataset.
Breach Breakdown
5,033 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds