TelROI Breach Handed Hackers MD5 Hashes and Birthdates
HEROIC analysts identified a data breach affecting TelROI, an e-commerce retailer based in La Reunion, France, surfaced on August 6, 2024. The breach exposed 19,029 records from the company's online store customer database, including email addresses, first names, last names, birthdates, and MD5 password hashes. The incident was classified as a database compromise, with the data appearing on underground forums shortly after exfiltration.
Why This Is Dangerous: MD5 is a deprecated hashing algorithm that modern password-cracking hardware can reverse for common passwords in seconds. Attackers who obtain these hashes can quickly recover plaintext passwords and use them to break into any account where the victim reused the same credentials. The addition of birthdates makes this dataset particularly potent: date of birth is routinely used as a verification factor by banks, insurers, and government services, meaning attackers can bypass identity verification checks without needing any other information.
What Was Exposed
- Email addresses
- First names
- Last names
- Birthdates
- Password hashes (MD5)
Why This Matters
When a breach combines a crackable password format like MD5 with personally identifying information such as full name and date of birth, the risk profile jumps significantly. Attackers can crack the passwords to gain account access, then use the real identity data to pass knowledge-based authentication challenges at financial institutions. This opens the door to account takeover, fraudulent loan applications, unauthorized wire transfers, and full identity theft. Affected customers face risk not just on the TelROI platform, but on every service where they used the same email and password pair.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a platform's backend data store. Common entry points include SQL injection attacks targeting input fields, exploitation of unpatched software vulnerabilities, or theft of database credentials through phishing. Once access is established, the attacker can dump entire customer tables within minutes. The extracted files are then packaged and posted to hacking forums or sold in private channels, where buyers use automated tools to crack passwords and launch credential stuffing campaigns at scale.
Check If You Are Affected
HEROIC's free breach scanner checks your email address against more than 400 billion compromised records, including this TelROI dataset. Find out immediately whether your information was part of this breach and what to do next. Scan your email for free now.
Breach Breakdown
19,029 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds