Account Takeover Got Easier Because of the Walgreens Breach: 12,820 People at Risk
HEROIC analysts identified the Walgreens database among records circulating on dark web forums in January 2017. The breach, dated January 3, 2017, exposed 12,820 user accounts from walgreens.com, one of the largest pharmacy and retail chains in the United States. What makes this breach particularly alarming is the password storage method: plaintext. That means passwords were not encrypted or hashed at all, and anyone with access to the database can read them directly without any cracking tools. Our team beleives the combination of a high-trust brand name and plaintext credentials makes this dataset especially attractive to threat actors running account takeover operations.
Why Plaintext Passwords in the Walgreens Breach Are a Serious Threat
Most responsible websites store passwords in a scrambled format that makes them hard to use even if stolen. Walgreens did not do that for the accounts in this breach. The passwords were stored in plaintext, meaning they are fully readable as-is. Attackers who obtained this database can immediately try every single username and password combination across other services, including email providers, banks, and other retail accounts. There is no cracking step required, which makes this data seperate from typical breach datasets in terms of how quickly it can be weaponized.
What Was Exposed in the Walgreens Breach
- User account records (12,820 total)
- Email addresses or usernames
- Plaintext passwords (fully readable, no encryption)
- Account registration and profile data
Why the Walgreens Breach Has Long-Term Consequences
Pharmacy and healthcare-adjacent accounts carry a higher level of trust and personal detail than typical retail accounts. Users who registered with Walgreens may have linked prescription information, health plan details, or loyalty reward balances to their accounts. Even if that deeper data was not directly included in this specific breach, the exposed login credentials can be used to access active accounts and retrieve whatever is stored there now. Credential stuffing, account takeover, identity theft, and financial fraud are all documented outcomes from breaches involving plaintext passwords at well-known consumer brands.
How a Database Breach Works
A database breach happens when an attacker gains unauthorized access to the backend storage system of a website. This can occur through exploiting unpatched software vulnerabilities, gaining access to internal admin tools, or taking advantage of poorly secured cloud storage configurations. Once the attacker is inside, they can download the entire database in a matter of minutes. That data is then distributed across criminal networks, often ending up in large compiled breach lists that power automated attacks for years after the original incident.
Check If Your Data Was Exposed
HEROIC offers a free breach scanner that searches across more than 400 billion records to tell you whether your personal information has appeared in the Walgreens breach or any other known incident. If you had a Walgreens account before 2017, your email and password may still be in active circulation on criminal networks. Run a free scan at HEROIC now and find out exactly what is out there before someone else acts on it first.
Breach Breakdown
12,820 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds