Poshmark data breach (2018)
In May 2018, the social-commerce marketplace Poshmark was breached and roughly 36 million user accounts were exposed, including email addresses, names, usernames, genders, locations and bcrypt-hashed passwords. The company confirmed the incident in August 2019.
- Victim
- Poshmark
- records
- 36.4M
- users
- 36.4M
In May 2018, the U.S. social-commerce marketplace Poshmark suffered a data breach that exposed roughly 36.4 million user accounts. The company did not confirm the incident publicly until 1 August 2019, after the stolen database began surfacing on underground markets.
What happened
Poshmark operates a peer-to-peer marketplace for buying and selling clothing and accessories. At some point around 16 May 2018, an unauthorized third party obtained a copy of the company's user database. Poshmark has not publicly detailed the intrusion vector, and no threat actor has been formally attributed. The incident only became visible more than a year later, when the dataset was offered for sale โ reportedly for around $750 โ and subsequently shared with breach-tracking services.
On 1 August 2019, Poshmark published a security notice acknowledging that "certain information" had been acquired by an unauthorized party. The same dataset was added to Have I Been Pwned on 2 September 2019, where it was logged at 36,395,491 accounts.
Data exposed
The compromised records included:
- Email addresses
- Names and usernames
- Gender and city/location data
- Clothing size preferences
- Passwords stored as bcrypt hashes (salted per user)
Poshmark stated that no financial information and no physical addresses were compromised. Because passwords were protected with bcrypt โ a deliberately slow, salted hashing function โ they were not immediately usable. However, bcrypt is not unbreakable: weak or common passwords can still be cracked offline. Within weeks of the dataset circulating, security researchers reported that roughly one million Poshmark passwords had been cracked and were being sold.
Response
Poshmark urged all users to reset their passwords as a precaution. By 9 September 2019, the company strengthened this stance, forcing a password reset at login for any account that had not changed its password since the 1 August disclosure. The company emphasized its use of bcrypt as a mitigating control and reported no evidence of fraudulent activity tied directly to the exposed data.
Why it matters
The Poshmark breach is a textbook example of the long gap between compromise and disclosure that characterized many mid-2010s incidents: data taken in 2018 only became public knowledge in 2019. It also illustrates both the value and the limits of bcrypt password hashing โ strong hashing bought time and blunted the immediate impact, but it did not prevent weak passwords from eventually being cracked and resold. For users who reused their Poshmark password elsewhere, credential-stuffing remained the principal downstream risk.
Timeline
Unauthorized third party accesses Poshmark's user database, the date later associated with the breach.
Poshmark publicly confirms the breach and recommends all users reset their passwords.
The 36.4-million-account dataset is loaded into Have I Been Pwned.
Poshmark begins forcing a password reset at login for anyone who had not yet changed their password since 1 August.
Roughly one million cracked Poshmark passwords are reported circulating for sale online.
Sources
- haveibeenpwned.comhttps://haveibeenpwned.com/Breach/Poshmark
- techcrunch.comhttps://techcrunch.com/2019/08/01/poshmark-confirms-data-breach/
- blog.poshmark.comhttps://blog.poshmark.com/2019/08/01/important-security-notice-from-poshmark/
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/cracked-passwords-for-poshmark-accounts-being-sold-online/
- securityaffairs.comhttps://securityaffairs.com/90712/data-breach/poshmark-cracked-passwords.html