[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1v49jozq3s3yj":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":30,"seoTitle":31,"seoTitleEn":32,"seoDescription":31,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":35,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda48825405","Wanelo","Wanelo Data Breach","wanelo","wanelo.com","2018-12-13T00:00:00.000Z","2019-09-30T17:15:11.000Z","2019-10-01T05:39:41.000Z","2026-07-19T16:31:35.908Z","Verified social shopping platform data breach","https:\u002F\u002Fwww.zdnet.com\u002Farticle\u002Fa-hacker-has-dumped-nearly-one-billion-user-records-over-the-past-two-months\u002F",[16,18],"https:\u002F\u002Fwanelo.com\u002F",23165793,"known",null,"unknown","Critical",[25,26,27,28,29],"Email addresses","IP addresses","Names","Passwords","Physical addresses","\u003Cp>The Wanelo data breach affected 23,165,793 unique email addresses and related account data in December 2018. Data from the social-shopping and digital-marketplace platform was offered for sale in April 2019 alongside records stolen from other companies. The verified scope includes email addresses, IP addresses, names, passwords, and physical addresses. Those fields were not all delivered in the same record structure; \u003Cstrong>23,165,793 unique email addresses\u003C\u002Fstrong> define the account scope, but they do not establish that all five data types were exposed for every user.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>Email addresses and passwords were the main fields described in the original sale listing. Approximately three million passwords were reportedly stored as MD5 hashes, while the remainder used bcrypt. \u003Cstrong>MD5 and bcrypt password hashes do not provide equivalent protection:\u003C\u002Fstrong> MD5 is fast and unsuitable for modern password storage, whereas bcrypt is designed to slow offline guessing, though its effectiveness still depends on the configured cost and the strength of each password. Additional data supplied later included names, shipping addresses, and IP addresses. Because those fields were not directly associated with the email-and-password records, the evidence does not support treating every field as one joined profile for a specific person. Phone numbers, payment cards, banking details, dates of birth, and identity documents are not verified data classes for this record.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The canonical reference date is 13 December 2018, while the published account describes the incident more generally as occurring around December 2018. In April 2019, the data was listed in a sale batch covering six companies and allegedly containing 65.5 million user records; the Wanelo portion was advertised as roughly 23 million records. Later independent verification refined the Wanelo scope to 23,165,793 unique email addresses. Public reporting did not detail the initial-access method, the attacker's dwell time, or when the underlying weakness was fixed. Attributing the incident to a particular software vulnerability, configuration error, or employee account would therefore be speculative. The password formats and data groups can be described with confidence, but the technical intrusion path cannot.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People who reused their Wanelo password on another service face the greatest account-takeover risk. MD5 hashes are particularly exposed to rapid guessing when the original password was weak or common; records protected with bcrypt are more resistant, but password reuse still creates risk after recovery or cracking. Users whose email addresses appeared may receive convincing fake reset notices, shopping promotions, or delivery messages. Names and shipping addresses in the supplementary group can make fraud attempts appear more personal, while IP addresses may provide approximate network or location context. It remains important that the supplementary name, address, and IP fields were \u003Cstrong>not directly linked\u003C\u002Fstrong> to the email-and-password set, so the separate data groups should not be represented as a complete profile for every account.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>If the password once used at Wanelo is still active anywhere else, replace it immediately with a long, unique password. Do the same for passwords built from minor variations, because automated attacks routinely test predictable changes. Enable multi-factor authentication on important services, beginning with the email account used for password recovery, and review active sessions and recovery methods. Avoid links in unexpected Wanelo-themed order, shipping, refund, or discount messages; type the known website address yourself. After any suspicious sign-in alert, change the password, revoke existing sessions, and check whether email, phone, or delivery settings were altered without permission. Payment data is not part of the verified scope of this record, but unexplained financial activity should still be reported to the relevant institution as a general safety measure.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>A password manager that creates a different credential for every service is one of the most effective ways to stop an old breach from spreading to other accounts. Prefer app- or hardware-key-based multi-factor authentication where it is available. Protect the email account used as your recovery hub by periodically reviewing forwarding rules, connected applications, backup contacts, and sign-in history. Removing obsolete delivery addresses from shopping accounts and requesting deletion of unused accounts can reduce the data available in a future incident. For service operators, modern password-hashing settings, data minimization, separation of access between datasets, anomaly monitoring, and timely incident notification are durable controls that limit the consequences of a breach.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Search your email address in LeakData to see whether it matches the Wanelo breach record. Only query an address that belongs to you or that you are authorized to review. A match means the address appears in the verified Wanelo dataset; it does not prove that the password was recovered, the account was taken over, or the name, physical address, and IP fields appeared in that same record. An empty result should not override a trusted security notice received through another channel, because dataset coverage can change over time. If there is a match, replace reused passwords first, then review the recovery and active-session settings of the associated email account.\u003C\u002Fp>","","Wanelo Data Breach (23.2 Million Reported Records)","Wanelo Data Breach. 23.2 Million reported records were reported. Reported data: Email addresses, IP addresses, Names. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fwanelo_com.webp",false,{"name":7,"sector":37,"country":38,"website":10,"websiteArchiveUrl":31,"websiteStatus":31,"websiteCheckedAt":21},"Social shopping and e-commerce","United States"]