Blog

Poshmark Retailer Member Passwords Are Being Sold Online

By baypointetech September 20, 2019

There is grim news for users of the online marketplace Poshmark, which is a thriving community where people buy and sell used clothing and other accessories. Recently it has come to light that the login details of more than 36 million of the company's 40 million members were acquired by an unauthorized third-party.


Worse, those details have been found for sale on the Dark Web.


The stolen data was fairly extensive and included each user's username, real name, email address, gender, geographic location, and hashed password. If there's a silver lining to be found in the aftermath of the incident, it is the fact that Poshmark disclosed the breach promptly. They reported that they had used the bcrypt algorithm to hash user passwords, which makes it less likely, (though not impossible), for the hackers to actually gain access to those passwords.


Unfortunately, there appears to be steady demand for the Poshmark data. Despite the fact that Poshmark did its part by protecting their members' passwords with a strong hashing algorithm, the sad truth is that many users have bad password habits. Thus, the hackers reasoning, a majority of the passwords being protected are notoriously weak and those accounts may be able to be accessed via brute force methods.


This latest incident underscores three key points:


  • Anyone online should begin to develop better password habits immediately.
  • Anywhere two-factor authentication is available, it should also be used.
  • If you're a Poshmark customer, you should change your password immediately.



These pieces of advice are no different today than they were when we talked about the last major breach, and they'll be identical to the advice given when we talk about the next one. The hackers won't stop until and unless we make it not worth the effort.


Used with permission from Article Aggregator

Related Posts

By Mersad September 23, 2025
How can a small-scale establishment stand out in today's competitive market? With the shift toward digital-first experiences, mobile apps help businesses stay relevant and accessible, no matter their size. Learn more about them here.
By Mersad September 22, 2025
Many businesses across various industries have already implemented a remote work model. Around 35% of Silicon Valley workers, for example, now work from home, a sharp rise from the 2019 pre-pandemic period's 6%, and for good reason. This shift brings many worthwhile advantages, including:
By Mersad September 20, 2025
There’s no question that the traditional username and password combination is a weak link when it comes to online security. For several years, experts have encouraged businesses to implement passkeys to overcome the pitfalls of traditional passwords, which have become increasingly vulnerable to cybercriminals.
By Mersad September 19, 2025
Just how safe is your establishment from online threats? A new phishing scam is making waves and targeting US-based organizations. Learn more about it here so you can bolster your defenses.
By Mersad September 18, 2025
Are you finding it harder to keep your offerings profitable over time? By investing in innovation, establishments can predict and control physical wear, combat obsolescence, and even discover new utilization opportunities. Learn more about technology for longer product lifecycles here.

Contact Information

1035 Medina Rd, Suite #800

Medina, OH 44256