TerraTrike Data Breach: 9,297 Customer Accounts Exposed with Mixed Hash Security
Mixed Hash Algorithms and a Michigan Trike Maker: The TerraTrike Breach
TerraTrike -- manufactured by WizWheelz Inc. in Grand Rapids, Michigan -- built a reputation for quality recumbent tricycles. Their data security implementaion, however, told a more inconsistant story. A breach in August 2018 exposed 9,297 accounts with a mixed bcrypt and PHPass hash scheme -- suggesting the platform had migrated between security standards without completeing a full transition, leaving some accounts better protected than others.
TerraTrike (August 2018): Breach Summary
- Records Exposed: 9,297
- Data Types: Email addresses, password hashes
- Breach Type: Database breach / Combolist
- Password Hash Type: Mixed bcrypt + PHPass -- inconsistent security implementation across accounts
- Country Affected: United States
- Date Leaked: August 26, 2018
What Mixed Hash Algorithms Reveal About Security Practices
Finding both bcrypt and PHPass hashes in the same credential database is a distinctive forensic signature. It typically indicates one of two scenarios: either the platform migrated from PHPass (a legacy PHP-based scheme used in WordPress and older CMSs) to bcrypt at some point, with old accounts retaining their original PHPass hashes and new accounts receiving bcrypt -- or the platform used a CMS with its own password handling that was later supplemented with custom code.
Bcrypt is considered strong and resistant to brute-force attacks at current computing capabilities. PHPass, by contrast, is a legacy scheme designed for backwards compatibility -- while better than MD5, it is significantly more vulnerable than bcrypt at high iteration counts. This means that within the TerraTrike dataset, some accounts are substantially more at risk than others.
Manufacturing Sector Breaches: A Pattern of Underinvestment
Specialty manufactuerer websites -- recumbent trikes, industrial equipment, niche sporting goods -- frequently prioritize product quality over digital security infrastructure. The IT resources available to a Michigan trike manufacturer differ substantially from those at a dedicated e-commerce platform. This creates a predictable vulnerability pattern: consumer-facing e-commerce functionality (accounts, logins, purchase history) built on legacy CMS platforms without dedicated security review.
The TerraTrike breach fits this pattern precisely. A small but real dataset of customer accounts, stored with inconsistent security implementation, eventually folded into combolist circulation.
Small Volume, Long-Tail Risk: Why 9,297 Records Still Matter
With only 9,297 records, the TerraTrike breach is not a mass-scale exposure. But small datasets carry their own risk profile: the user base is self-selected, likely composed of genuine outdoor recreation enthusiasts with real purchasing power and consistent email addresses. Credential stuffing attacks don't require scale -- they require accurate, unique email/password combinations that haven't appeared in larger, more well-known breaches.
For users who registered specifically on TerraTrike -- and may not realize the site was breached -- the risk remains live if credentials were reused elsewhere.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records to determine whether your email address appears in known data breaches, including the TerraTrike combolist. Run a free scan at HEROIC.com to check your exposure and take action before attackers do.
Breach Breakdown
9,297 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds