E-commerce marketplace Storenvy was reportedly breached, exposing about 1.5 million user accounts in a leak that included credentials stored in plain text. Reports said the compromised data contained usernames, email addresses, IP addresses, and passwords, sharply increasing the risk of account takeover, credential stuffing, and follow-on compromise for users who reused the same passwords on other services.
The incident stood out because the leaked passwords were allegedly not hashed, reflecting weak credential protection practices at the time of the breach. Users affected by the exposure were urged to reset their Storenvy passwords immediately, change any reused passwords on other platforms, and enable stronger account protections where available, while defenders were advised to watch for phishing and suspicious login activity tied to the leaked records.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
404 Media reported unauthorized changes to Ukraine frontline maps and said the edits appeared to point toward Polymarket's war-betting activity. The reference indicates disclosure of the suspected manipulation but provides no earlier specific date than publication.
NBC News reported that the compromise of Microsoft's email system was becoming more severe, indicating a significant escalation or newly understood impact in the incident. The reference does not provide a more specific event date than the publication date.
E-commerce firm Storenvy was reported hacked, with about 1.5 million user accounts exposed. The leaked data reportedly included plaintext account credentials, making this the key disclosed event in the reference.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
nbcnews.com
Open source404media.co
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.