TendersUnlimited Data Breach: 14,468 Kenyan Procurement Accounts Exposed
Business Procurement Credentials at Risk: The TendersUnlimited Breach
TendersUnlimited operated in one of the more sensitive sectors of B2B digital services: connecting Kenyan suppliers and contractors with public and private sector procurment opportunities. When 14,468 supplier accounts were exposed in August 2018 with MD5-hashed passwords, the breach created more than a typical credential exposure -- it handed attackers a directory of Kenyan business operators actively engaged in public tenderring processes.
TendersUnlimited (August 2018): Breach Summary
- Records Exposed: 14,468
- Data Types: Email addresses, password hashes
- Breach Type: Database breach / Combolist
- Password Hash Type: MD5 -- fast algorithm with no salt, vulnerable to rainbow table attacks
- Country Affected: Kenya
- Date Leaked: August 26, 2018
B2B Platform Exposure: Beyond Individual Risk
When a consumer platform is breached, individual users face credential reuse and phishing risks. When a B2B procurement platform is breached, the risks scale differently. TendersUnlimited users were not casual internet consumers -- they were business owners, procurement officers, and suppier representatives actively participating in Kenya's formal tender economy. Their email addresses and account access represent business intelligence in themselves.
An attacker with access to this dataset knows which businesses were active in the Kenyan procurement market in 2018, their contact information, and potentially the tender categories they participated in. This is actionable intelligence for targeted business email compromise (BEC) campaigns.
MD5 Crackability: How Fast Are These Passwords at Risk?
TendersUnlimited stored passwords using MD5 without salting -- a configuration that makes the dataset particularly vulnerable to precomputed rainbow table attacks. Modern GPU-accelerated cracking tools can test billions of MD5 hashes per second. For a dataset of 14,468 records, a competent attacker would expect to recover a substantial portion of passwords within hours using standard wordlist attacks.
Common passwords -- variations of business names, years, or simple phrases -- are particularly vulnerable. B2B platform users often select convenient rather than secure passwords, making this dataset more crackable than a typical consumer platform of similar size.
Supply Chain Intelligence and Long-Term Risk
Public sector tender participation data has long-term value for attackers targeting supply chains. Knowing which suppliers were active in Kenyan government procurement in 2018 provides a targeting list for subsequent social engineering attempts -- particularly impersonation attacks designed to redirect tender awards or payment details. While direct credential access via combolist stuffing is the immediate risk, the intelligence value of this dataset extends to broader business fraud scenarios.
African B2B platforms have historically received less attention from international cybersecurity researchers, meaning breaches like TendersUnlimited often circulate for years before being widely indexed and flagged.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records to determine whether your email address appears in known breaches, including the TendersUnlimited combolist. Kenyan business operators who used the platform should run a free scan at HEROIC.com to identify any ongoing credential exposure.
Breach Breakdown
14,468 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds