Data breach
Promofarma
- Records
- 4,940,765
- Breach date
- 1 January 2021Estimated
- Added
- 1 December 2024
What was exposed
1 type of data · 2 more reported
- Email addresses4,940,765
- PasswordsReported, not counted
- IP addressesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Promofarma, a Spanish online pharmacy based in Barcelona, has been linked to a large dataset of customer records that surfaced on underground leak listings in 2021. According to our investigation team, the indexed listing for promofarma.com contains approximately 4.9 million rows, with an estimated breach date of January 1, 2021.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
One of the clearest external traces of this dataset comes from SOCRadar, a cybersecurity firm that catalogs large leaked databases. Its listing for promofarma.com, posted on September 2, 2021, describes a 517 MB compressed file attributed to the Spanish healthcare sector. Promofarma operates as an e-commerce pharmacy selling medications and health products to customers primarily in Spain and Portugal. The company has not published a public breach notice that we could locate in sources reviewed as of September 25, 2026.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses.
The catalog entry does not specify how many of the roughly 4.9 million rows include email addresses, so that count remains unknown.
The SOCRadar listing, which describes the same dataset, adds further detail. It reports around 4.9 million user records with hashed email addresses, roughly 2.5 million hashed passwords, some email addresses and IP addresses stored in plaintext, about 2.7 million lines of account security alerts, roughly 423,000 product listings tied to accounts, about 423,000 coupon codes, and around 471,000 product ratings.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Even hashed email addresses can be valuable to attackers, who use large email lists for phishing and spam campaigns. If your email address appears in this dataset, you may receive convincing messages that reference pharmacy orders, prescription products, or account problems, designed to trick you into clicking malicious links.
The presence of hashed passwords matters if you reused the same password on Promofarma and other sites. Attackers can attempt to crack weakly hashed passwords, and matching credentials across services allows account takeovers elsewhere. Plaintext IP addresses and email addresses add detail that makes phishing more credible.
The coupon codes and account activity records are less sensitive, but they can still be used to add legitimacy to fraudulent messages.
What Should You Do If You Were Affected?
Take these steps:
Change your Promofarma password immediately, and change it anywhere else you used the same or a similar password.
Use a unique password for every account, and consider a password manager to keep track of them.
Turn on two-factor authentication wherever the service offers it, especially on your email account.
Be cautious with unexpected emails about orders, prescriptions, coupons, or account security. Avoid clicking links in them, and go to the website directly instead.
Watch for follow-up phishing attempts. Attackers often use breached email lists months or years after the initial leak.
Review any account statements connected to online shopping for unfamiliar activity.
If you notice signs that an account of yours was accessed without permission, contact the affected service's support team and report the incident.
