A Quiet 2018 Leak Still Exposes 10,831 Ciberdúvidas Accounts
HEROIC analysts found a dataset tied to Ciberdúvidas da Língua Portuguesa, a well-known online resource for the Portuguese language, resurfacing on a dark web marketplace after originally leaking on a hacking forum. The breach dates back to August 26, 2018, and exposed 10,831 records made up of email addresses and password hashes stored in an unconfirmed format.
Why This Is Dangerous
Unlike a plaintext leak, these passwords were hashed, meaning they were scrambled before storage rather than left fully readable. That offers some protection, but hashes can still be cracked, especially with older or weaker hashing methods, and once cracked they become just as usable as if they'd leaked in plain text. The quiet resurfacing of this dataset years later shows that old, seemingly forgotten breaches don't simply disappear; they get recirculated and reused.
What Was Exposed
- Email addresses of Ciberdúvidas users
- Password hashes, stored in an unconfirmed hashing format
Why This Matters
A breach doesn't have to make headlines to matter. This one sat quietly for years before turning up again on a dark web marketplace, which means anyone who registered on this site and never changed their password could still be at risk today. Attackers who successfully crack hashed passwords add them to combolists and test them against email providers, banking sites, and other services, which is how a low-profile leak from 2018 can still lead to account takeover, identity theft, or financial fraud in the present day.
How Database and Combolist Breaches Work
This breach started as a direct database compromise, where an attacker extracted user records straight from Ciberdúvidas's backend systems. Because the passwords were hashed rather than left in plaintext, they required extra effort to crack, which may explain why the data has continued circulating for years rather than being used up quickly. Once cracked, credentials like these are folded into combolists, large combined lists of email and password pairs traded and sold across hacking forums and dark web marketplaces, kept in use long after the original breach fades from memory.
Check If You Are Affected
You can check whether your email address is part of this breach or any other using HEROIC's free breach scanner, which searches a database of more than 400 billion leaked and breached records. If you find a match, change that password anywhere you may have reused it, even if the original breach happened years ago.
Breach Breakdown
10,831 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds