Breach Intelligence Report 18 Sep 2025

TendersUnlimited Data Breach: 14,468 Kenyan Procurement Accounts Exposed

HEROIC
HEROIC Threat Intelligence Team
Email Address Password Hash
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 14,468
Source Type Database,Combolist
Origin Darkweb
Password Type MD5

Business Procurement Credentials at Risk: The TendersUnlimited Breach

TendersUnlimited operated in one of the more sensitive sectors of B2B digital services: connecting Kenyan suppliers and contractors with public and private sector procurment opportunities. When 14,468 supplier accounts were exposed in August 2018 with MD5-hashed passwords, the breach created more than a typical credential exposure -- it handed attackers a directory of Kenyan business operators actively engaged in public tenderring processes.


TendersUnlimited (August 2018): Breach Summary

  • Records Exposed: 14,468
  • Data Types: Email addresses, password hashes
  • Breach Type: Database breach / Combolist
  • Password Hash Type: MD5 -- fast algorithm with no salt, vulnerable to rainbow table attacks
  • Country Affected: Kenya
  • Date Leaked: August 26, 2018

B2B Platform Exposure: Beyond Individual Risk

When a consumer platform is breached, individual users face credential reuse and phishing risks. When a B2B procurement platform is breached, the risks scale differently. TendersUnlimited users were not casual internet consumers -- they were business owners, procurement officers, and suppier representatives actively participating in Kenya's formal tender economy. Their email addresses and account access represent business intelligence in themselves.

An attacker with access to this dataset knows which businesses were active in the Kenyan procurement market in 2018, their contact information, and potentially the tender categories they participated in. This is actionable intelligence for targeted business email compromise (BEC) campaigns.


MD5 Crackability: How Fast Are These Passwords at Risk?

TendersUnlimited stored passwords using MD5 without salting -- a configuration that makes the dataset particularly vulnerable to precomputed rainbow table attacks. Modern GPU-accelerated cracking tools can test billions of MD5 hashes per second. For a dataset of 14,468 records, a competent attacker would expect to recover a substantial portion of passwords within hours using standard wordlist attacks.

Common passwords -- variations of business names, years, or simple phrases -- are particularly vulnerable. B2B platform users often select convenient rather than secure passwords, making this dataset more crackable than a typical consumer platform of similar size.


Supply Chain Intelligence and Long-Term Risk

Public sector tender participation data has long-term value for attackers targeting supply chains. Knowing which suppliers were active in Kenyan government procurement in 2018 provides a targeting list for subsequent social engineering attempts -- particularly impersonation attacks designed to redirect tender awards or payment details. While direct credential access via combolist stuffing is the immediate risk, the intelligence value of this dataset extends to broader business fraud scenarios.

African B2B platforms have historically received less attention from international cybersecurity researchers, meaning breaches like TendersUnlimited often circulate for years before being widely indexed and flagged.


Check If Your Data Was Exposed

HEROIC's free breach scanner searches across more than 400 billion exposed records to determine whether your email address appears in known breaches, including the TendersUnlimited combolist. Kenyan business operators who used the platform should run a free scan at HEROIC.com to identify any ongoing credential exposure.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Password Hash
Password Types MD5
Date Leaked 18 Sep 2025
Check in 5 seconds

14,468 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,028 scanned today
Breach Rank #10,255 by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $104.7K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance