[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3hk9pxgfyhh8z":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":30,"seoTitle":31,"seoTitleEn":32,"seoDescription":31,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":35,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda488251b2","estante-virtual","Estante Virtual Data Breach","estantevirtual.com.br","2019-02-28T00:00:00.000Z","2023-11-29T22:13:34.000Z","2026-07-09T23:07:56.264Z","2026-07-18T23:50:20.645Z","Online book marketplace breach","https:\u002F\u002Fdehashed.com\u002Finsights\u002Festantevirtual-com-br-data-breach-2019-february",[15],5412603,"known",null,"unknown","Critical",[23,24,25,26,27,28,29],"Dates of birth","Email addresses","Names","Passwords","Phone numbers","Physical addresses","Usernames","\u003Cp>\u003Cstrong>Estante Virtual data breach\u003C\u002Fstrong> is a significant e-commerce security incident linked to the leakage of personal and account information of customer accounts of the Brazil-based online book marketplace in February 2019. The verified record scope should be considered as 5,412,603 affected accounts. Since Estante Virtual is a platform that brings together book buyers, independent sellers, and second-hand book dealers within the same marketplace, this incident should not be seen merely as a login problem; the leaked data has the potential to simultaneously affect a person's contact information, address context, account identifiers, and password security. Therefore, individuals using an Estante Virtual account need to consider the possibility that the same email address or password may also have been used for other shopping, payment, social media, or email services.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Among the types of data confirmed in this incident are names, usernames, email addresses, physical addresses, phone numbers, birth dates, and passwords. The fact that passwords are stored in unsalted SHA-1 format increases the risk; because although this type of password hash theoretically provides protection even for strong, unique, and long passwords, it can facilitate guessing and matching attacks for weak or reused passwords. The combination of email address and username can help attackers recognize the person across different accounts. Phone number and physical address information, on the other hand, can be used in targeted scams such as fake delivery notifications, fake customer service calls, payment renewal pretexts, or account verification traps.\u003C\u002Fp>\n\u003Cp>Date of birth alone is not proof of financial identity; however, when combined with address, phone, and email information, the risk becomes more tangible. An attacker could use this combination to prepare messages that appear aligned with a person's shopping habits, try to guess password reset questions, or attempt to take over accounts on other platforms using the same information. In the context of a book marketplace, users' reading preferences, seller-buyer relationships, and delivery history can also make social engineering scenarios more convincing. Therefore, not only the security of the Estante Virtual account should be reviewed, but also other accounts opened with the same contact information.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified number of affected accounts used as the basis for this record is 5,412,603, and the date of the breach is recorded as February 28, 2019. In some data inventories, the raw row count may appear higher; however, the raw row count does not always correspond to unique individuals or unique customers. Multiple rows belonging to the same user, seller profile, address component, account field, or recurring data element can be counted as separate records. Therefore, for the publicly available record, the verified number at the level of 5.4 million should be used for the account impact, and higher row claims should not be presented as the number of unique victims.\u003C\u002Fp>\n\u003Cp>Data types should be evaluated in a limited manner, with fields such as name, username, email address, physical address, phone number, date of birth, and password. In this record, the verified data classes should be kept limited to the above personal contact information, account identifiers, and password fields. Even though password information is present, it should not be assumed that it was exposed in the same way for all users or that all passwords were in plain text; the record should be described in terms of the risk of securely salted SHA-1 password hashes. This distinction is important both to provide the user with the correct level of risk and to avoid overstating the scope of the incident.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>In the highest risk group are people who use the password from their Estante Virtual account on other services as well. If the same password is repeated on an email account, shopping sites, social media profiles, or payment-linked platforms, attackers can use the information obtained from previous data sets in automated login attempts. Especially if the email account is compromised, a much wider account chain can be affected through password reset links. Therefore, the passage of time since the breach does not eliminate the risk; if the old password is still used elsewhere, the danger persists.\u003C\u002Fp>\n\u003Cp>Sellers, regular buyers, book collectors, and users who have not updated their physical address on the platform for a long time also carry a separate risk. Seller profiles may receive more targeted messages due to commercial communication, delivery addresses, and customer relations. Buyers, on the other hand, can be deceived with fake order notifications, return requests, shipping updates, or excuses for account reactivation. Users with a phone number should be more cautious against SMS and call-based frauds; users with a date of birth should be more careful against attempts targeting identity verification questions. For people who have been using the same email address for years, the risk of profiling increases when this data is combined with other old leaks.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The priority is to determine whether the password used on the Estante Virtual account is still being used anywhere else. If the same or a similar password is valid for another account, a unique, long, and strong password should be set for each service. Changing the password should not be limited to Estante Virtual; it should also include shopping, email, payment, social media, and cloud accounts where the same email and password combination is used. Using a password manager makes it easier to detect repeating passwords and generate strong passwords.\u003C\u002Fp>\n\u003Cp>Multi-factor authentication should be enabled for the email account, and recent sessions and password reset activities should be checked. Since phone numbers and address information may have been leaked, unexpected shipping messages, fake customer service calls, account verification links, and payment update requests should be examined carefully. Personal information such as date of birth or address should not be used as a password, PIN, or answer to security questions. Account recovery options should be updated, and old recovery emails and phone numbers that are no longer in use should be removed.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Such old but still effective data breaches require users to permanently change their password habits. Using a unique password for each account, enabling multi-factor authentication wherever possible, and regularly closing old accounts are basic protective steps. Instead of using the same email address across all services, users can prefer separate addresses or masking solutions for critical accounts. This way, a data set from a shopping platform cannot be directly matched with financial or personal communication accounts.\u003C\u002Fp>\n\u003Cp>From an institutional perspective, the Estante Virtual incident highlights the importance of password storage methods and data minimization. Password hashes should be protected with modern, slow, and salted algorithms; data such as addresses, phone numbers, and birth dates should be deleted when no longer required; and seller and buyer data should be protected with separate access controls. On the user side, keeping an inventory of old accounts, closing unused accounts, using email aliases, and regularly reviewing security notifications reduces the likelihood of long-term harm.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If you have used Estante Virtual or have previously opened an account on estantevirtual.com.br, you need to check whether your email address is associated with this incident during registration verification. If you see a match, first identify other accounts using the same password, then change the passwords of these accounts to unique values. Simply reusing the old password with minor changes is not enough; attackers can automatically try common password variations. Prioritize your email account, because the recovery process for other accounts usually goes through email.\u003C\u002Fp>\n\u003Cp>Fields such as phone number, address, and date of birth also broaden the impact of the incident, so do not be satisfied with just changing your password. When dealing with messages themed around shipping, book orders, returns, payments, account verification, and customer support, check the domain name before clicking on links. When interacting with people asking for your information, hang up the call and perform the action by opening the official site yourself. This record has been prepared to turn the verified account impact and types of leaked data of the Estante Virtual data breach into user action; the goal is to show the risk clearly without exaggeration, highlighting password reuse and the possibility of targeted fraud.\u003C\u002Fp>","","Estante Virtual Data Breach (5.4 Million Reported Records)","Estante Virtual Data Breach. 5.4 Million reported records were reported. Reported data: Dates of birth, Email addresses, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Festantevirtual_com_br.webp",false,{"name":37,"sector":38,"country":39,"website":9,"websiteArchiveUrl":31,"websiteStatus":31,"websiteCheckedAt":19},"Estante Virtual","E-commerce","Brazil"]