[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fdxsgky1pehh8":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":27,"seoTitle":16,"seoTitleEn":28,"seoDescription":16,"seoDescriptionEn":29,"logoUrl":30,"isVerified":4,"isSensitive":4,"isSpamList":31,"isMalware":31,"company":32},"68e3266eda11adda4882512c","bud-trader","BudTrader Data Breach","budtrader","budtrader.com","2024-06-27T00:00:00.000Z","2024-10-01T13:51:19.000Z","2025-10-08T18:45:04.645Z","2026-07-18T23:46:48.210Z","Third party breach","",[],2721185,"known",null,"unknown","Critical",[24,25,26],"Email addresses","Passwords","Usernames","\u003Cp>BudTrader is now known as a cannabis-focused social platform and listing community that is no longer active. The data breach dated June 2024 affected approximately 2.7 million email addresses, usernames, and WordPress password hashes, along with the data that was put up for sale in July 2024.\u003C\u002Fp>\u003Cp>The BudTrader account should be handled sensitively due to the nature of the platform. The matching of email and username poses a privacy risk not only in terms of account security but also in terms of associating the person with a cannabis-themed community. Therefore, the explanation should focus on both password repetition and the impact on privacy.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The data classes tracked in the BudTrader record should be treated as email addresses, password data, and usernames. Email addresses can be used for targeted phishing, password reset schemes, and account matching across different services. Password data directly increases the risk of account compromise, especially if the same password is reused on other services. Usernames can help to link pseudonyms across different platforms and personalize social engineering messages.\u003C\u002Fp>\u003Cp>Although password hashes are not plain text, they pose an account guessing risk in weak or reused passwords. The platform context can be used to send users messages about counterfeit products, payment, delivery, investment, advertising, or community invitations.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>This record is associated with the domain name budtrader.com and the June 2024 period. The scope is limited to email addresses, usernames, and password data. Purchase, payment card, address, or private message fields should not be added as verified data class for this record.\u003C\u002Fp>\u003Cp>Fields that are not present in this record should not be described as if they have leaked. Fields such as full card number, account password, official ID, private message, device content, or health information should only be included in the risk assessment if they are explicitly present in the record. The text is based on verifiable data classes and the known boundaries of the incident.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Users who have opened a BudTrader account, people who use the same nickname on different social platforms, members who want to keep a low profile in cannabis-themed communities, and users who reuse the same password on other accounts are at higher risk.\u003C\u002Fp>\u003Cp>Users who use the same email address across different services, repeat their old passwords, and share their phone and address information across many shopping or community accounts are at higher risk. The connection between a pseudonym and real identity in corporate or community accounts can create additional social engineering risks.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users should update their BudTrader password and all accounts where they used the same password pattern. Be cautious of hemp-themed counterfeit products, payment, advertising, or community invitations; personal or payment information should not be shared.\u003C\u002Fp>\u003Cp>Users in the positive match area should update their passwords on accounts where they use the same or similar passwords, enable two-factor authentication where possible, and check recent sessions. Caution should be exercised against unexpected calls, deliveries, returns, support, and verification messages on records containing phone numbers, addresses, payment information, or sensitive community information.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Using a separate email address and a unique username in communities with sensitive topics reduces privacy risks. Users should monitor their accounts on old or closed platforms and try to prevent archived usernames from matching with other accounts.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is found in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset, and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result indicates that the email address appears in the BudTrader dataset and requires attention in terms of both password security and privacy. A negative result simply means there is no match within this record.\u003C\u002Fp>","BudTrader Data Breach (2.7 Million Reported Records)","BudTrader Data Breach. 2.7 Million reported records were reported. Reported data: Email addresses, Passwords, Usernames. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fbudtrader_com.webp",false,{"name":33,"sector":34,"country":35,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"BudTrader","Cannabis Social Platform","United States"]