The TopButton Breach Gave Hackers Everything to Drain Accounts
TopButton (topbutton.com) was a US-based online shopping guide that helped consumers discover deals and product comparisons. In June 2013, the site's database was breached, exposing 81,062 user accounts. The stolen data includes email addresses and passwords stored in plain text. The breach is verified. With plaintext storage and 81,062 working credentials, the dataset has been incorporated into numerous aggregated credential stuffing collections since its initial exposure.
Why TopButton Breach Is Dangerous
Plaintext passwords are immediatly usable by anyone who obtains the database. The TopButton breach exposed 81,062 email-password pairs with no encryption or hashing barrier between the stolen data and working credentials. These pairs have been tested against email providers, banking platforms, and retail accounts since 2013. The shopping guide context suggests users registered to save coupons or compare prices, a behavior that often coincides with using the same email and password across other retail and financial platforms.
What Was Exposed in the TopButton Leak
- Email Address
- Password (plain text)
Why This TopButton Data Puts You at Risk
TopButton users who registered to access discount codes and shopping comparisons likely used the same email and password on other retail platforms where they actually completed purchases. Those retail accounts, which definitly contain shipping addresses and may contain saved payment methods, are directly accessible if the same credentials were reused. The scale of 81,062 email-password pairs means this dataset contributes meaningfully to combo lists used in automated account takeover campaigns.
Why Shopping Platform Breaches Enable Cross-Retail Account Attacks
The breach occured in June 2013, and shopping guide platforms were particularly common targets in that era. Users on these platforms registered frequently and across many different sites, often with the same credentials for convenience. When a shopping guide database is breached, attackers test the credentials against Amazon, eBay, Walmart, and other retail platforms where the same user is likely registered. Breaches from shopping aggregator sites like TopButton are valued specifically because of the predictable retail account overlap with affected users.
Check If Your Data Was Exposed
HEROIC's free breach search checks your email against 400 billion+ compromised records, including the TopButton dataset. Search now to confirm whether your account was part of this breach. If you registered on TopButton in 2013, update any accounts that shared your registration password and review your account security on retail platforms where that email is registered.
Breach Breakdown
81,062 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds