Quidd, an online marketplace that sells stickers, cards, games, and other collectibles, was hacked in 2019, resulting in the leak of data from about 4 million users to hacking forums. This data included Quidd usernames, email , and passwords from hacked accounts. A hacker known as PROTAG appears to be behind the leak of this data.
In the cybercrime world , there are various groups and entities, each of which plays a different role. For example, there are hackers who carry out the actual security breaches, and there are data traders, that is, people who sell the stolen data. Two different sources told ZDNet that a hacker known as ProTag is the one who appears to be behind the breach in question and who first leaked the Quidd data for sale. In addition, ZDNet learned from a data trader that Quidd information had been for sale for months, with ads related to it being posted on hacking forums and Pastebin around October and December 2019, respectively. But while this data had been privately negotiated for months, Quidd user information has now been leaked publicly. This happened last month, when a data trader posted a copy of Quidd's data on a public hacking forum. Since then, the data has been shared and republished among other members of the hacking community.

Quidd has not disclosed any recent security, making it unclear whether the company is aware of the breach. ZDNet reached out to Quidd about the incident but has not yet received a response. Having received copies of the leaked data, it has also contacted some users to confirm that their details were correct.
Risk-Based Security, which first reported the Quidd breach last week, also said that after initial testing, the data appears to be valid. The only positive thing about the leaked data is that the passwords were not in plain text, but were secured with the bcrypt algorithm . Reversing encrypted passwords back to their plain text form is considered extremely difficult and requires time and resources. Ironically, the use of the bcrypt algorithm may be the reason why the Quidd data has been leaked to public hacking forums. The trader is referring to the fact that spam , malware, and online fraud groups are interested in pirated data containing clear text passwords, since it is easier to take control of these accounts and run their respective spam, malware , and fraud campaigns .

There are a number of hackers currently trying to crack Quidd passwords. One person is selling access to more than 135,000 hidden Quidd passwords, while Risk-Based Security reports that it has identified another person who claims to be providing access to more than 1 million compromised Quidd accounts. Quidd users are advised to change their passwords as soon as possible.
