How the Shop of Coins Database Breach Led to 6,047 Stolen Accounts
HEROIC analysts found the Shop of Coins database exposed in May 2023, containing approximately 6,600 records from the Russian collectible coins and banknotes e-commerce platform. The dump included 6,047 unique email addresses along with phone numbers, full names, IP addresses, and MD5 hashed passwords. What stood out immediately was the use of MD5 for password storage. MD5 has been considered cryptographically broken for years, meaning passwords hashed with it can often be reversed in minutes using widely accessable cracking tools.
MD5 Passwords From Shop of Coins Can Be Cracked Fast
Attackers who obtained this database do not need to guess passwords one by one. MD5 hashes can be matched against precomputed rainbow tables or cracked using GPU clusters at enormous speed. A realistic attacker can reverse a large portion of common passwords within hours. Once they have cleartext passwords paired with email addresses and phone numbers, they can attempt logins on other services those customers use, contact victims directly via phone for social engineering, or sell the cracked credential pairs to other criminal groups. The inclusion of phone numbers in this breach is seperate from most database dumps and adds a direct contact vector that makes follow-on fraud much easier.
What Was Exposed in the Shop of Coins Breach
- Email addresses (6,047 unique)
- MD5 password hashes
- Phone numbers
- First and last names
- IP addresses
Why This Breach Creates Real Fraud Risk
The combination of email addresses, phone numbers, full names, and crackable passwords is a particularly dangerous package. Credential stuffing attacks use this data to take over accounts on other platforms. Identity theft schemes use the names and contact details to impersonate victims or open fraudulent accounts. Phone numbers enable SIM-swap attacks, where a criminal convinces a carrier to transfer your number, bypassing two-factor authentication on banking and other high-value accounts. Even collectors who only used Shop of Coins for hobby purchases are at genuine risk of broader financial fraud.
How the Shop of Coins Database Breach Happened
Smaller e-commerce platforms like Shop of Coins often run on off-the-shelf software that is not regularly updated or audited. The most common attack path for a database breach like this is SQL injection, where an attacker submits malicious input through a product search or login form to trick the server into returning database contents. Another common vector is a compromised admin account obtained through phishing. Either way, once an attacker is recieved into the backend with sufficient access, pulling the entire user table is a matter of a few queries. The data is then archived and distributed through underground channels, where it eventually surfaces in breach monitoring systems like HEROIC.
Check If Your Data Was Exposed
HEROIC's free dark web scanner covers over 400 billion records collected from breaches across the globe, including the Shop of Coins dump. Type your email address into the free scanner at HEROIC.com to find out in seconds whether your credentials or personal information appeared in this breach or any other known exposure. It is free, instant, and shows you exactly what was leaked.
Breach Breakdown
6,047 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds