Analysts Link 185,049 Leaked Accounts to the Abraham-Hicks Breach
HEROIC analysts identified the Abraham-Hicks breach while monitoring dark web forums for recirculating credential dumps tied to U.S.-based personal development and spirituality platforms. In March 2018, the website abraham-hicks.com suffered a database breach that exposed 185,049 user records. The compromised data included email addresses, plaintext passwords, and password hashes. The presence of unencrypted plaintext passwords in a 2018 breach is seperate from typical poor security cases, as this level of negligence put every affected user at direct and immediate risk.
What Attackers Can Do With Hashed and Plaintext Passwords Together
Having both plaintext passwords and password hashes in the same dump gives criminals a major advantage. The plaintext passwords can be used immediately for account takeover attempts, while the hashed passwords can be fed into cracking tools to recover even more credentials. Attackers beleive that users who register on niche platforms often reuse the same email and password combination on their primary accounts, including email, banking, and social media, making this breach far more dangerous than its size suggests.
What Was Exposed in the Abraham-Hicks Breach
- Email Address
- Password Hash
- Plaintext Password
Why Breaches of Personal Development Platforms Carry Extra Risk
Users of spirituality and personal development websites often share deeply personal beliefs, purchase histories, and event registrations alongside their login credentials. When that data ends up in the wrong hands, the risk extends beyond simple account takeover. Criminals can use email addresses to craft highly targeted phishing messages that reference the platform by name, making victims far more likely to click. Credential stuffing attacks using this data occured long after the original breach date, and the risk continues today for anyone who reused their password.
How a Database Breach Works
A database breach happens when an attacker finds a way into the back-end storage system of a website. Common methods include exploiting software vulnerabilities, using stolen administrator credentials, or injecting malicious code into database queries. Once access is gained, the attacker can copy or download the entire user database, which typically includes login details and any other information users submitted when creating their accounts. Organizations that fail to encrypt passwords or apply basic security patches make these attacks far easier and more damaging.
Check If Your Data Was Exposed
HEROIC provides a free breach scanner backed by a database of more than 400 billion exposed records. If you ever had an account on Abraham-Hicks or any similar platform, you can run a free scan right now to see if your email address or password has appeared in a known breach. Do not wait to find out the hard way.
Breach Breakdown
185,049 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds