TradeKeyIndia Data Breach: 21,028 Records Exposed
B2B Marketplace Credentials at Risk: The TradeKeyIndia Breach
TradeKeyIndia was an India-focused B2B marketplace connecting Indian supplyers and manufacturers with global buyers -- a platform designed to facilitate international trade by providing a directory of Indian exporters across industries including textiles, chemicals, agricultural products, and industrial equipment. When the site's database was breached on August 26, 2018, it exposed 21,028 user accounts with plaintext passwords: the worst possible credential storage outcome for a platform handling business-to-business commercial relationships.
TradeKeyIndia (August 2018): Breach Summary
- Records Exposed: 21,028
- Data Types: Email addresses, plaintext passwords
- Breach Type: Database breach
- Password Type: Plaintext -- immediate usability for account takeover; no cracking required
- Country: India
- Date Leaked: August 26, 2018
B2B Platform Credentials and Supply Chain Risk
Consumer data breaches get the most coverage, but B2B platform exposures carry a distinct set of risks. TradeKeyIndia's users were not casual shoppers -- they were buisness owners, export managers, procurement agents, and international trade facilitators. Credentials associated with this demographic may be reused on GST filing portals, customs and shipping platforms, bank trade finance accounts, or international payment services like PayPal Business, Wise, or Payoneer.
A plaintext credential set from a B2B trade directory is a targeted asset for business email compromise campaigns. Attackers who know that an email address belongs to an Indian exporter can craft convincing invoice fraud, wire transfer requests, or supply chain impersonation attacks -- scenarios that have cost businesses globally billions of dollars annually.
Indian B2B Ecommerce and the Export Sector
India's export sector -- particularly in textiles, pharmaceuticals, and light manufacturing -- relies heavily on B2B platforms to connect with international buyers. Many small and medium-sized Indian exporters registerd on multiple directories and platforms in the mid-2010s, often using the same business email and password across all of them. A plaintext breach of one platform creates exposure across the entire ecosystem of tools that exporter uses.
The combolist classification of this breach means TradeKeyIndia credentials have been aggregated with other datasets and distributed for automated testing. Business email accounts associated with Indian exporters are tested against a wide range of platforms -- including Indian banking portals like HDFC NetBanking, ICICI, and State Bank of India -- wherever credential reuse may have occurred.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records, including Indian B2B marketplace breaches like TradeKeyIndia. If your business email appeared in this breach, check your exposure and audit any platform where that credential combination may have been reused.
Breach Breakdown
21,028 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds