Data breach
Wanelo
- Records
- 23,166,688
- Breach date
- 13 December 2018Estimated
- Added
- 4 March 2025
What was exposed
2 types of data · 3 more reported
- Email addresses23,166,688
- Home addresses23,166,688
- PasswordsReported, not counted
- NamesReported, not counted
- IP addressesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In December 2018, Wanelo, a social shopping website that let users save and share products from online stores, suffered a data breach that exposed the records of roughly 23 million accounts. According to our investigation team, the breach exposed 23,166,688 email addresses and 23,166,688 home addresses. The data surfaced publicly months later, when a hacker offered it for sale on a dark web marketplace as part of a large batch of stolen records.
Breach Timeline
December 13, 2018: The breach of Wanelo occurred, according to the Mozilla Monitor breach database.
April 15, 2019: A hacker using the name Gnosticplayers put Wanelo user data up for sale on the dark web marketplace Dream Market as part of a batch of records from six companies, as reported by Digital Information World and other outlets.
September 30, 2019: The breach was verified and added to the Mozilla Monitor database.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and home addresses, totaling 23,166,688 records each.
External breach databases add further detail. Mozilla Monitor lists passwords, names, and IP addresses among the compromised data, and notes that some passwords were stored as weak MD5 hashes while others used the stronger bcrypt algorithm. A cybersecurity notice from Berry College, which counted campus email addresses among the affected accounts, likewise warned that the exposed passwords should be treated as compromised regardless of how they were stored.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
An email address paired with a home address is a strong foundation for targeted phishing. Scammers can use a real name, address, and shopping history context to craft convincing messages that look like order confirmations, delivery notices, or account warnings, and physical mail fraud becomes easier when a valid home address is already attached to an email account.
If passwords were exposed as well, as external reporting indicates, the risk extends beyond Wanelo. Anyone who reused the same password on other sites could face credential stuffing, where attackers try stolen passwords across many services. Weakly hashed passwords are also easier for attackers to crack before reselling or publishing them.
What Is Wanelo Doing in Response?
We could not confirm any public statement from Wanelo about the breach or about notifying affected users as of September 25, 2026. The site's data reached breach-monitoring databases through third-party researchers rather than a company announcement. Affected users should therefore assume the responsibility for protecting their accounts rests with them.
What Should You Do If You Were Affected?
If you had a Wanelo account, take these steps:
Change your Wanelo password if you still use the account, and change it anywhere else you reused the same password.
Choose a long, unique password for each service, ideally with a password manager.
Turn on multi-factor authentication wherever it is offered.
Be cautious with emails or letters referencing orders, deliveries, or your Wanelo account, especially if they ask you to click links or confirm personal details. Go to websites directly instead of following links in messages.
Watch for suspicious physical mail, such as fake invoices or prize notifications, since a home address was part of the exposed data.
In the news
- Mozilla Monitor – Wanelo Data Breachmonitor.mozilla.org (opens in a new tab)
- Berry College – Data Breach Notification: Wanelocybersecurity.berry.edu (opens in a new tab)
- Digital Information World – Hacker releases a massive data dump containing nearly 1 billion users' datadigitalinformationworld.com (opens in a new tab)
