A RaidForums user has posted a database that allegedly belongs to the site Offrea, containing over half a million user records and three thousand login details. As the user details in the post, the administrators used very weak passwords and outdated software, so taking advantage of SQL injection potential was trivial. The hacker further alleges that they tried to contact the website administrators multiple times, starting in March 2021, but they never received any response.
Offrea.be is a Belgian site that allows users to find professional craftsmen and technicians for various works on their home, like cleaning, plumbing, fixing electrical problems, maintaining AC units, building roofs, doing gardening, etc. The site has over 3,000 registered professionals, which matches the number of leaked credentials and claims to serve 6,800 orders each month.
The user records supposedly contain names, email addresses, physical addresses, and IP addresses, while the login details are limited to names, email addresses, and passwords. French journalist Damien Bancal has sampled the data to confirm its validity, and indeed he has found the promised details inside the nine databases that constitute the leaked pack.
If you have used Offrea services in the past, treat your credentials as compromised, so go ahead and reset them from wherever you were using them. Additionally, stay alert against phishing and scamming attempts, especially those that use this very incident as a hook. To our knowledge, Offrea is not circulating any notices of a breach, and even if they did, they wouldn’t ask you to share any personal or sensitive details to confirm your identity or whatever. If an email takes you to a login site, supposedly for resetting your password, pay attention to the URL and validate it before you type anything.
Update Sep. 17: Offrea has provided the following comment to TechNadu: