State Beauty Supply Data Breach Exposes 38,380 User Passwords
HEROIC's DarkHive intelligence system discovered the State Beauty Supply data breach, exposing 38,380 records from a now-defunct Kansas City beauty shopping website. The breach occured in June 2019 and leaked email addresses and plaintext passwords, with the data appearing in combolists that attackers continue to use for credential stuffing attacks years after the initial incident.
Why This Is Dangerous
Plaintext password breaches from retail and e-commerce sites are particularly damaging because shoppers tend to reuse thier passwords across many different services including banking, email, and social media. The 38,380 exposed credentials from State Beauty Supply have been incorporated into large credential stuffing combolists that attackers use to automate login attempts against hundreds of websites simultaneously. Even though the original site is no longer operational, the stolen passwords remain valid on every other platform where the victims reused the same credentials.
What Was Exposed
- Email Address
- Plaintext Password
Why This Matters
Data from older breaches does not expire in terms of usefulness to criminals. Attackers regularly acquire datasets from years-old breaches and run them through credential stuffing tools against current websites and services. Users who recieve login alerts or notice unauthorized activity on accounts they haven't actively used should check whether their email appears in breach databases like this one. Identity theft and account takeover remain serious risks for anyone whose information appears in the State Beauty Supply combolist.
How Database and Combolist Breaches Work
A combolist is created when breached credential databases from multiple sources are merged into a single file containing millions of email and password pairs. Attackers use these combolists with automated tools to test credentials against popular websites and services at scale. E-commerce sites like State Beauty Supply are common targets for database theft because they store both payment information and account credentials, and thier security is often less robust than dedicated financial platforms.
Check If You Are Affected
HEROIC offers a free identity scanner that searches over 400 billion records, including data from breaches like State Beauty Supply. Visit heroic.com to scan your email address and find out if your information was exposed.
Breach Breakdown
38,380 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds