The Wanelo Leak Could Unlock Your Bank, Email, and Social Accounts
HEROIC analysts identified the Wanelo breach during a review of recirculated e-commerce credential dumps in December 2018. The breach occured when attackers accessed the digital mall's user database, exposing 21,451,647 records containing email addresses and password hashes. The data resurfaced on dark web marketplaces in April 2019 and has continued circulating in underground forums, particularly in collections labeled as "e-commerce combos."
How Stolen Email and Password Hash Combos Enable Account Takeover
With email addresses and password hashes in hand, attackers can crack weakly hashed MD5 passwords within hours using standard tools. Those cracked credentials are then fed into automated stuffing tools that test them against banking portals, email providers, and social media platforms. Because Wanelo was a shopping platform, the exposed credentials are partcularly attractive for targeting retail and payment accounts where users tend to reuse the same login.
What Was Exposed in the Wanelo Breach
- Email Address
- Password Hash
Why Wanelo's Mixed Hashing Makes This Especially Dangerous
The Wanelo breach stored passwords using both MD5 and bcrypt. MD5 hashes are effectively plaintext to modern cracking rigs, meaning a significant portion of the 21 million accounts are directly accessable to attackers right now. Even bcrypt-protected accounts face risk if users chose weak passwords. In real-world terms, this means credential stuffing campaigns, account takeovers, fraudulent purchases, and identity theft can all flow from a single six-year-old breach that never fully went away.
How Database Breaches Work
A database breach occurs when attackers gain unauthorized access to a backend data store, typically by exploiting unpatched vulnerabilities, SQL injection flaws, misconfigured cloud storage, or stolen administrative credentials. Once inside, they export user tables containing account details and password hashes. The stolen data is then sold or traded on dark web markets, often appearing in large combo lists that aggregate multiple breaches for use in automated attacks.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion records to tell you instantly whether your email appeared in the Wanelo breach or any other known incident. Run a free scan at HEROIC and find out what attackers may already know about your credentials.
Breach Breakdown
21,451,647 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds