Breach Intelligence Report 25 Jul 2022

Researchers Trace the StockX Breach to 6.3 Million Stolen Credentials Sold on Dark Web

HEROIC
HEROIC Threat Intelligence Team
Email Address Username Ip Salt First Name Last Password Hash
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 6,335,147
Source Type Database
Origin Darkweb
Password Type MD5(Salt)

HEROIC analysts identified the StockX breach as a significant database exposure that occured in July 2019, compromising 6,335,147 records from the popular sneaker and fashion trading platform. The leaked dataset contained email addresses, usernames, IP addresses, salts, first names, last names, and password hashes stored using salted MD5, making it a rich target for credential attacks against users who recieved accounts on this platform.


How Salted MD5 Password Hashes and Full Names Enable Targeted Account Takeovers

StockX stored passwords as MD5 hashes with salts, a method that is considered weak by modern standards. Attackers with access to first names, last names, email addresses, and salted MD5 hashes can run targeted cracking campaigns using GPU-accelerated tools. Once cracked, the plaintext passwords combined with real names make credential stuffing attacks partcularly effective because they allow attackers to craft personalized phishing lures alongside automated login attempts across dozens of platforms.


What Was Exposed in the StockX Breach

  • Email Address
  • Username
  • IP Address
  • Salt
  • First Name
  • Last Name
  • Password Hash

Why 6.3 Million StockX Records Remain a Threat to Users and Enterprises

The scale of the StockX breach means that a meaningful portion of the US sneaker and fashion enthusiast demographic had their credentials exposed. Many of these users are beleived to have reused the same email and password combination across financial platforms, retail accounts, and workplace systems. The salted MD5 hashes have had years to be cracked, and the inclusion of IP address data makes it accessable for attackers to profile user behavior and identify corporate network origins for secondary targeting.


How Database Breaches Work

A database breach occurs when attackers gain unauthorized access to a backend data store, typically through exploiting a vulnerability, misconfigured cloud storage, or compromised administrative credentials. Once access is obtained, the entire user table can be exported in a single operation. In the StockX case, the data was subsequently sold on dark web marketplaces, where it circulated broadly among threat actors looking for credential datasets to use in automated attacks.


Check If Your Data Was Exposed

HEROIC's free breach scanner searches across more than 400 billion records to determine whether your email address appears in the StockX breach or any other known incident. Run a free scan now and find out what attackers may already know about your credentials.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Username,IP Address,Salt,First Name,Last Name,Password Hash
Password Types MD5(Salt)
Date Leaked 25 Jul 2022
Check in 5 seconds

6,335,147 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,224 scanned today
Breach Rank #N/A by affected users
Impact Score
40
sensitivity + scale + recency
Est. Financial Impact $45.8M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance