Security Researchers Find 5,072 Brikers Records for Sale
HEROIC analysts identified a dataset tied to Brikers, a United States based eCommerce platform, circulating on a hacking forum. The breach dates back to August 26, 2018, and exposed 5,072 records made up of email addresses paired with MD5 hashed passwords.
Why This Is Dangerous
MD5 has been considered insecure for password storage for well over a decade, since modern hardware and freely available tools can crack large batches of MD5 hashes relatively quickly. That means researchers examining this leak can reasonably expect that a significant share of these passwords have already been converted from hashes back into plain, usable text by anyone who bothered to try.
What Was Exposed
- Email addresses of Brikers customers
- Password hashes, secured using the outdated MD5 algorithm
Why This Matters
A cracked password from an old shopping account rarely stays confined to that one site. Analysts consistently observe attackers testing recovered credentials against email providers, banking platforms, and other services, betting that the same person reused their password elsewhere. For anyone who shopped at Brikers around 2018 and never changed that password, the risk of credential stuffing, account takeover, identity theft, and financial fraud remains very real today.
How Database and Combolist Breaches Work
This incident began as a direct compromise of Brikers's database, where an attacker gained access and extracted stored customer records, including the MD5 hashed passwords. Because MD5 offers little real protection by modern standards, the data's value to attackers didn't diminish much once it was exfiltrated. It surfaced on a hacking forum, where researchers and criminals alike routinely find leaked credentials merged with data from other breaches into combolists, large combined files used to automate login attempts across the internet.
Check If You Are Affected
You can check whether your email address appears in this breach or any other using HEROIC's free breach scanner, which searches a database of more than 400 billion leaked and breached records. If you're affected, change that password immediately anywhere else you may have used it.
Breach Breakdown
5,072 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds