[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fj1oww9ifo48q":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":4,"isSpamList":38,"isMalware":38,"company":39},"68e3266eda11adda48825121","bookchor","Bookchor Data Breach","bookchor.com","2021-01-28T00:00:00.000Z","2022-07-03T23:41:38.000Z","2026-07-09T17:01:47.506Z","2026-07-18T23:46:24.690Z","Third party breach","https:\u002F\u002Fbreaches.sencode.co.uk\u002Fbreaches\u002Fbookchor",[15,17,18],"https:\u002F\u002Fwww.twingate.com\u002Fblog\u002Ftips\u002Fbookchor-data-breach","https:\u002F\u002Fwww.goincognito.co\u002Falert-498297-breached-accounts-at-online-book-trading-website\u002F",498297,"known",null,"unknown","High",[25,26,27,28,29,30,31,32],"Dates of birth","Email addresses","Genders","IP addresses","Names","Passwords","Phone numbers","Social media profiles","\u003Cp>The Bookchor data breach is related to the exposure of customer records on the India-based second-hand book buying and selling platform bookchor.com. The incident was recorded on January 28, 2021, and the verified impact is at the level of 498,297 accounts. Since Bookchor is an e-commerce\u002Fcommunity service operating around book purchasing, selling, and sharing, the leaked data affects not only account login security but also users' identity and contact privacy.\u003C\u002Fp>\n\u003Cp>The verified data classes for this record are birth dates, email addresses, gender information, IP addresses, names, passwords, phone numbers, and social media profiles. Passwords have been reported to be stored as unsalted MD5 hashes. The MD5 structure without salt is considered weak; it poses a serious risk especially for short, predictable, or reused passwords across other accounts. Therefore, users who see matches should check not only their Bookchor account but also all accounts where they use the same password pattern.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>In the Bookchor breach, email addresses, names, phone numbers, dates of birth, gender information, IP addresses, social media profiles, and passwords are verified data fields. When email and phone are found together, the user may become vulnerable to both email and message\u002Fcall-based fraud attempts. Name, date of birth, and gender information can be used to generate messages that appear more personal.\u003C\u002Fp>\n\u003Cp>Social media profiles can help attackers recognize the user on other platforms and establish connections between accounts. Having passwords in unsalted MD5 format increases the risk level. When no salt is used, the same passwords produce the same output, making comparison with common password lists easier. If the same password is used for email, social media, shopping, or work accounts, this breach can turn into a chain account takeover risk.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified scope of this record is 498,297 accounts and eight data classes: dates of birth, email addresses, gender information, IP addresses, names, passwords, phone numbers, and social media profiles. Payment card, bank account, physical address, government ID, or order content are not among the verified fields for this record. The description should be based only on the verified data classes.\u003C\u002Fp>\n\u003Cp>Bookchor records should be evaluated in the context of book trade and second-hand book platforms. No additional violation assumption should be made for other book sites, publishers, or sales platforms with a similar name. The number in the record reflects the singular account effect; raw row counts or repeated records may appear differently. User action should be planned based on the verified 498,297 accounts and listed data fields.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Users in the highest risk group are those who reuse the password they use for their Bookchor account on other accounts. Students, users who buy and sell books, and people who use the same email\u002Fphone information on different shopping sites may be targeted more. Fields such as date of birth and social media profile can lead to the user being deceived with campaigns, shipping, account verification, or book sale messages that appear more realistic.\u003C\u002Fp>\n\u003Cp>Users with a phone number and social profile link can be targeted not only via email but also through messaging apps and social media. Therefore, the risk assessment should not be limited to just changing the password. Users need to be cautious about unexpected links, payment requests, second-hand book buying and selling messages, and account recovery alerts.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Users who find a match should first identify the password they used on their Bookchor account and any other accounts where the same password pattern was used. If the same or a similar password is still in use on another account, it should be changed immediately. Priority should be given to email accounts, social media, shopping, payment-related services, educational platforms, and work accounts. A unique and long password should be created for each account.\u003C\u002Fp>\n\u003Cp>Care should be taken against fake cargo notifications, book orders, payment confirmations, account verifications, or campaign messages because email, phone, and social profile information has been exposed. Instead of logging in through links received, one should go directly to the relevant service, unexpected files should not be opened, and account recovery information should be updated. Two-step verification should be enabled for critical accounts, and application-based verification should be preferred if possible.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Bookchor incident shows that services combining e-commerce and community features create extensive personal data profiles. Users should regularly review fields such as birth date, phone number, and social profile shared in their shopping, book, education, and community accounts. Accounts that are no longer in use should be closed, unique passwords should be used for those that cannot be closed, and profile information should be stripped of unnecessary details.\u003C\u002Fp>\n\u003Cp>On the corporate side, such incidents show that password storage methods, customer data segmentation, access control, and incident reporting processes should be considered together. On the user side, password managers, multi-factor authentication, leaked password checks, and phone\u002Femail-based fraud awareness should be implemented together. Weak password storage structures like unsalted MD5 can cause older data sets to pose a risk for years.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>Finding a match with an email address in this record indicates that the user is present in the Bookchor dataset. The user should first determine which password they used on their Bookchor account, and then check whether the same password or similar variations have been used on other accounts. Since phone and social media information is also present, attention should be paid not only to email alerts, but also to messaging and social network notifications.\u003C\u002Fp>\n\u003Cp>A match does not prove that the password was transmitted in plain text; however, the exposure of unsalted MD5 password hashes and personal messaging fields is sufficient for security action. Using unique passwords, two-factor authentication, checking incoming messages directly from a trusted channel, and closing old accounts significantly reduce the risks of account takeover, phishing, and targeted fraud that may arise from the Bookchor breach.\u003C\u002Fp>","","Bookchor Data Breach (498.3 Thousand Reported Records)","Bookchor Data Breach. 498.3 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fbookchor_com.webp",false,{"name":40,"sector":41,"country":42,"website":9,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":21},"Bookchor","Online book marketplace","India"]