[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f318qr9tm7ch4m":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":22,"affectedCount":22,"affectedCountStatus":23,"affectedCountLowerBound":24,"affectedCountUnit":25,"hasEnglishDescription":4,"severity":26,"dataClasses":27,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":37,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"6a6e0707418013d8bc39572e","ChinaEKO2017","China EKO 2017 Data Breach","chinaeko-2017","chinaeko.com","2017-01-01T00:00:00.000Z","2026-08-01T14:47:35.080Z","Database leak","https:\u002F\u002Fwww.ransomlook.io\u002Fleak\u002F436",[14,16,17,18,19,20,21],"https:\u002F\u002Fbreachera.com\u002F","https:\u002F\u002Fleakedsource.com\u002Fbreaches\u002Fchinaeko-data-breach-0038bec0","https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Fchinaeko.com-2017","https:\u002F\u002Fdata-wells.niamonx.io\u002FBreach\u002FChinaEKO","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20160114201712\u002Fhttp:\u002F\u002Fwww.chinaeko.com\u002F","https:\u002F\u002Fapi.xposedornot.com\u002Fv1\u002Fbreaches",348555,"known",null,"records","High",[28,29,30,31],"Usernames","Email addresses","Password hashes","Password salts","\u003Cp>\u003Cstrong>The China EKO 2017 data breach\u003C\u002Fstrong> is associated with the exposure of 348,555 user records belonging to a former Chinese home-furnishings and building-materials shopping site. The reported fields are usernames, email addresses, password hashes and password salts.\u003C\u002Fp>\n\u003Cp>The record is dated January 2017 because that is the month reported by public sources. It represents month-level precision, not a confirmed day of unauthorized access.\u003C\u002Fp>\n\u003Ch2>What Is Known About the Incident?\u003C\u002Fh2>\n\u003Cp>China EKO operated at \u003Ccode>chinaeko.com\u003C\u002Fcode> and appears as 中国宜高 in Chinese-language material. Archived official pages confirm that it sold home decoration, furniture and building-material products.\u003C\u002Fp>\n\u003Cp>The exposed dataset is consistent with site-account fields. Publicly available reliable sources do not establish how initial access occurred, how long access persisted or who was responsible.\u003C\u002Fp>\n\u003Ch2>When Did the Breach Occur?\u003C\u002Fh2>\n\u003Cp>Multiple breach catalogs date the incident to January 2017. The catalog therefore uses 1 January 2017 to represent month precision; it does not claim that the incident occurred on that exact day.\u003C\u002Fp>\n\u003Cp>Later dataset-indexing dates are not treated as attack dates. No organization-issued incident notice was found, so the precise day of unauthorized access remains unconfirmed.\u003C\u002Fp>\n\u003Ch2>What Information Was Affected?\u003C\u002Fh2>\n\u003Cp>The reported data types are usernames, email addresses, password hashes and password salts. A salt is an additional input used for each password, but it does not provide sufficient protection by itself when an old or weak password-hashing method is used.\u003C\u002Fp>\n\u003Cp>Sources describe the password data as using a vBulletin-style structure. Plaintext passwords, payment cards, bank accounts and government identifiers have not been added because reliable evidence does not confirm that those fields were present.\u003C\u002Fp>\n\u003Ch2>How Could This Information Be Misused?\u003C\u002Fh2>\n\u003Cp>Password hashes may be subjected to offline guessing attacks. Reusing the same password on other services increases the risk that accounts outside China EKO could also be compromised.\u003C\u002Fp>\n\u003Cp>Email addresses and usernames may be used for targeted phishing, fraudulent password-reset messages and account-recovery attempts. Even when the original account is old, the same contact details may remain in use elsewhere.\u003C\u002Fp>\n\u003Ch2>What Should Users Do?\u003C\u002Fh2>\n\u003Cp>If a password used on China EKO was reused elsewhere, those accounts should be changed to strong, unique passwords. Using a different password for every service limits the spread of a single breach.\u003C\u002Fp>\n\u003Cp>Multi-factor authentication should be enabled wherever available. For unexpected password-reset, sign-in or account-recovery notices, visit the service's official address directly instead of following links in the message.\u003C\u002Fp>\n\u003Cp>If the same email address remains active, review unknown device sessions, forwarding rules and recovery options. Sign out active sessions and update recovery details if suspicious changes are found.\u003C\u002Fp>\n\u003Ch2>What Is the Verification Status?\u003C\u002Fh2>\n\u003Cp>The dataset size and field structure align across multiple independent catalogs and the technical summary of the source archive. These findings support the attribution to China EKO account data.\u003C\u002Fp>\n\u003Cp>The record is not marked as verified because no organization-issued incident notice or exact access date was found. The affected count follows the complete source-record total; differing parsing and deduplication results from other services are not presented as the same measurement.\u003C\u002Fp>","","China EKO 2017 Data Breach (348.6 Thousand Records)","The China EKO breach exposed 348,555 user records. Review the affected data types, date precision and practical account-security steps.","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20160418030601im_\u002Fhttp:\u002F\u002Fwww.chinaeko.com\u002Fimg\u002Flogo.gif",false,{"name":39,"sector":40,"country":41,"website":10,"websiteArchiveUrl":20,"websiteStatus":42,"websiteCheckedAt":12},"China EKO","Retail","China","parked"]