[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f27b8nec0b2cwy":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":33,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda48825290","MallCZ","MALL.cz Data Breach","mallcz","mall.cz","2017-07-27T00:00:00.000Z","2017-09-04T12:46:39.000Z","2026-07-18T23:53:59.535Z","E-commerce breach","https:\u002F\u002Fpulse.michalspacek.cz\u002Fpasswords\u002Fstorages\u002Fsite\u002Fwww.mall.cz",[15,17],"https:\u002F\u002Fwww.mall.cz\u002F",735405,"known",null,"unknown","High",[24,25,26,27],"Email addresses","Names","Passwords","Phone numbers","\u003Cp>The MALL.cz data breach is a significant security incident confirmed on July 27, 2017, affecting the e-commerce service based in the Czech Republic and impacting 735,405 unique user accounts. The main types of data observed in the record are email addresses, name information, phone numbers, and password data. The importance of the incident from the user's perspective is not limited to the risk of access to a shopping account; if the same information was reused with the same password on different services, it becomes valuable for account takeover, fake delivery messages, fraud under the pretext of returns, and targeted phishing attempts. Therefore, the MALL.cz data breach should be regarded as an incident where individuals with an e-commerce account need to review password security, messages received via phone, and old account records together.\u003C\u002Fp>\n\u003Cp>Verified information shows that the breach particularly affected accounts created before 2015. The detail on passwords should be interpreted carefully: different hash algorithms were used in the system at different times, and the readable passwords that got into circulation outside are likely to represent only the subset that was successfully cracked. This distinction is important; it should not be concluded that every account's password was directly available in readable form, but the risk is real and high for weak or reused passwords. MALL.cz users should consider accounts where they used the same password for email, payment, social media, marketplace, or courier services as part of the risk area related to the incident.\u003C\u002Fp>\n\u003Ch2>Types of Leaked Data and Their Risks\u003C\u002Fh2>\n\u003Cp>The types of data verified in the MALL.cz record consist of email addresses, name information, phone numbers, and password data. An email address alone can be used for targeted phishing messages, fake campaign announcements, and password reset attempts. Name information makes these messages appear more convincing; the attacker can create trust-inducing scenarios for the user, such as shopping history, delivery delays, or coupon notifications, by addressing the user by name. The phone number, on the other hand, increases the risk of fraud via text messages and calls.\u003C\u002Fp>\n\u003Cp>Password data is the most critical area. In the MALL.cz incident, it is understood that passwords were stored in a hashed form, but the algorithms used at different times were not equally strong. The likelihood that the passwords seen externally are a subset of compromised accounts increases the risk, especially for easily guessed passwords or those used on other sites. If a user has used the same password across different accounts, a single e-commerce breach could turn into a chain account takeover attempt.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>For this record, the verified scope consists of 735,405 unique accounts, with the breach date of July 27, 2017, and the types of data include email address, name, phone number, and password. The information that the incident is limited to accounts opened before 2015 indicates that old MALL.cz memberships should be specifically checked. There is no verified field in the record indicating the presence of payment card information, official ID number, full address, order content, or health data. Therefore, the risk assessment should be conducted based on the verified fields and without including exaggerated data claims.\u003C\u002Fp>\n\u003Cp>The limit regarding passwords should also be kept open. The fact that some passwords have become readable does not mean that all accounts' passwords are in the same situation. However, the strength difference between hash algorithms and the subset of cracked passwords indicate that accounts using old or weak passwords are at higher risk. Therefore, users who see a match in the MALL.cz registry should check not only the password for this service but also all accounts where the same or similar password is used.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The group at the highest risk are those who opened a MALL.cz account before 2015 and used the same password on other services as well. Since the email address used for the e-commerce account is often also used for banking, social media, package tracking, and other shopping sites, attackers can attempt different logins with the same identity. In particular, passwords that are short, contain dictionary words, or have been seen in previous breaches are the first targets in account takeover attempts.\u003C\u002Fp>\n\u003Cp>The risk of fraud also increases for users whose phone numbers have been leaked. Messages such as fake delivery fees, return requests, account verification excuses, or coupon notifications can be sent under the name MALL.cz or a similar e-commerce scenario. The phone number combined with name and email information helps the attacker reach the user in a more personal and convincing way. Therefore, not only online login attempts but also text messages and phone calls should be part of the security check.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If your MALL.cz account matches this incident, the first step is to change the password used on this account to a unique and strong password. Password changes should also be completed on email, social media, payment, marketplace, and shipping accounts where the same or similar password has been used. A different password should be used for each account, and if possible, long and random passwords should be created with a reliable password manager. Password reset messages and login alerts should also be reviewed separately.\u003C\u002Fp>\n\u003Cp>The second step is to enable two-factor authentication on all important accounts that support it. The email account is prioritized here, because the password reset process for many services proceeds via email. Instead of directly clicking on links from MALL.cz or similar e-commerce names, it is safer to manually enter the domain into the browser to start the process. Verification code requests received by phone, delivery fee payments, or return form links should also be evaluated with suspicion.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The MALL.cz data breach shows that old accounts need to be checked regularly. Unused e-commerce accounts should be closed, unnecessary personal information should not be stored in active accounts, and the same email-password combination should not be used on different services. Using a password manager makes it easier to maintain separate credentials for each service and reduces the reuse of previously leaked passwords. Security alerts, login notifications, and recovery email addresses should be reviewed at regular intervals.\u003C\u002Fp>\n\u003Cp>In the long term, users may also consider separating their email addresses according to different risk levels. The main email account can be used only for critical services, while shopping and membership addresses can be used for lower-risk transactions. Leaving the phone number blank if sharing it is not mandatory reduces the surface for SMS fraud. Since the effects of old breaches, such as MALL.cz, can persist even years later, regular account security habits provide better protection than a one-time password change.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If you see a match in the MALL.cz leak query, first identify which of your email addresses is in this record and line up the accounts associated with that address. First, the email account, then payment-linked services, shopping accounts, social media, and work accounts should be checked. Make sure a unique password is used for each account, and the old password should no longer be valid anywhere. Before opening any links in delivery, return, promotion, and account verification messages sent to your phone number, the sender and domain should also be checked.\u003C\u002Fp>\n\u003Cp>This record should not be treated as a verified breach of payment card or official ID data; however, the combination of email, name, phone, and password poses a serious account security risk. Users who opened a MALL.cz account especially before 2015 should try to remember their old passwords and complete the update process on all accounts where the same password is used. If you receive a suspicious login alert, an unexpected password reset message, or a notification of an order you do not recognize, check the security section of the relevant account without delay.\u003C\u002Fp>","","MALL.cz Data Breach (735.4 Thousand Reported Records)","MALL.cz Data Breach. 735.4 Thousand reported records were reported. Reported data: Email addresses, Names, Passwords. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fmall_cz.webp",false,{"name":35,"sector":36,"country":37,"website":10,"websiteArchiveUrl":29,"websiteStatus":29,"websiteCheckedAt":20},"MALL.cz","E-commerce \u002F Retail","Czech Republic"]