Researchers Trace the StockX Breach to 6.3 Million Stolen Credentials Sold on Dark Web
HEROIC analysts identified the StockX breach as a significant database exposure that occured in July 2019, compromising 6,335,147 records from the popular sneaker and fashion trading platform. The leaked dataset contained email addresses, usernames, IP addresses, salts, first names, last names, and password hashes stored using salted MD5, making it a rich target for credential attacks against users who recieved accounts on this platform.
How Salted MD5 Password Hashes and Full Names Enable Targeted Account Takeovers
StockX stored passwords as MD5 hashes with salts, a method that is considered weak by modern standards. Attackers with access to first names, last names, email addresses, and salted MD5 hashes can run targeted cracking campaigns using GPU-accelerated tools. Once cracked, the plaintext passwords combined with real names make credential stuffing attacks partcularly effective because they allow attackers to craft personalized phishing lures alongside automated login attempts across dozens of platforms.
What Was Exposed in the StockX Breach
- Email Address
- Username
- IP Address
- Salt
- First Name
- Last Name
- Password Hash
Why 6.3 Million StockX Records Remain a Threat to Users and Enterprises
The scale of the StockX breach means that a meaningful portion of the US sneaker and fashion enthusiast demographic had their credentials exposed. Many of these users are beleived to have reused the same email and password combination across financial platforms, retail accounts, and workplace systems. The salted MD5 hashes have had years to be cracked, and the inclusion of IP address data makes it accessable for attackers to profile user behavior and identify corporate network origins for secondary targeting.
How Database Breaches Work
A database breach occurs when attackers gain unauthorized access to a backend data store, typically through exploiting a vulnerability, misconfigured cloud storage, or compromised administrative credentials. Once access is obtained, the entire user table can be exported in a single operation. In the StockX case, the data was subsequently sold on dark web marketplaces, where it circulated broadly among threat actors looking for credential datasets to use in automated attacks.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion records to determine whether your email address appears in the StockX breach or any other known incident. Run a free scan now and find out what attackers may already know about your credentials.
Breach Breakdown
6,335,147 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds