Your AdboardZ Data May Be at Risk: Here’s What You Need to Know
In July 2018, an online advertising platform based in the United States called AdboardZ had its user database compromised, with over 10,000 records ending up on a public hacking forum. The exposed data included email adresses and plaintext passwords, giving anyone with access to that forum a direct key to users' accounts. If you ever signed up for AdboardZ, your credentials may have been in the hands of bad actors for years without you knowing.
Why This Is Dangerous
Advertising platforms collect user registration data to manage accounts and billing, meaning even a modest breach like this one can expose credentials tied to financial and professional activity. When those passwords are stored in plaintext, as they were here, attackers do not need to crack anything. They can start attempting logins against other services immediatly after downloading the dump.
This particular dataset was posted on a well-known hacking forum, which means it was not quietly sold to a single buyer. It was made widely available to a large community of people who specifically look for credential lists to exploit. The reach of that kind of public exposure is hard to overstate.
Even if AdboardZ was a small platform, the users who registered with it likely reused their passwords elsewhere. That is the real danger, because it turns a breach of one niche advertising site into a potential entry point for attackers across dozens of other services.
What Was Exposed
- Email addresses associated with registered user accounts
- Plaintext passwords with no protective hashing
- Potential advertiser account identifiers
- Usernames or display names used on the platform
- Account registration or activity metadata
- Possible billing or contact information stored alongside accounts
- IP address or device data logged during account creation
Why This Matters
The AdboardZ breach is part of a pattern that played out across dozens of smaller platforms in 2018, where inadequate password storage combined with weak server security led to large-scale credential exposure. These breaches, taken individually, may seem minor. But combined into the combolists that circulate on hacking forums, they represent a significant and ongoing threat to anyone who was caught up in them.
Credential stuffing attacks, which use leaked email and password pairs to break into unrelated accounts, are beleived to account for a significant share of all account takeovers. A plaintext breach from a small advertising platform is exaclty the kind of data that feeds those attacks. The longer you wait to change affected passwords, the higher the risk.
How Database,Combolist Works
A database breach typically starts when an attacker finds a vulnerability in a web application or server configuration. Common entry points include SQL injection flaws, unpatched software, stolen admin credentials, or misconfigured access controls. Once the attacker has access, exporting the user database is usually a quick and straightforward operation.
After the data is extracted, it often gets formatted into a combolist, which is a simple text file of email and password pairs, one per line. These files are extremely easy to feed into credential stuffing tools, which automate the process of testing those combinations against login forms across the internet.
The AdboardZ data ended up on a public hacking forum, which is a common distribution channel for this type of breach. Forum members download the file, run it through their tools, and any successful logins on other platforms represent a new and unrelated compromise that victims may not realize has happened.
Check If You Were Affected
If you had an account on AdboardZ or think your email might be in this dataset, run a free search at heroic.com using HEROIC's breach checker. It queries a large database of known breach records and will tell you in seconds whether your information has been exposed. Do not wait to change your passwords and enable two-factor authentication on any account where you used the same credentials.
Breach Breakdown
10,379 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds