The Admission Ads Breach Exposed More Accounts Than All Students at Harvard
HEROIC analysts identified the Admission Ads data breach, which occured in July 2018 and exposed 157,587 user records from a Pakistan-based educational platform. The leaked data included email addresses and plaintext passwords, meaning anyone who signed up for this service had their login credentials stored without any protection whatsoever. This breach has been circulating in underground forums, putting affected users at ongoing risk.
Why Plaintext Passwords Put You in Immediate Danger
When passwords are stored in plaintext, attackers do not need to crack anything. They simply read your password directly from the file. With email addresses and matching passwords in hand, criminals can attempt to log in to your other accounts recieved from any service where you used the same password, including email, banking, and social media. This is called credential stuffing, and it works because most people reuse passwords.
What Was Exposed in the Admission Ads Breach
- Email Address
- Plaintext Password
Why This Breach Still Matters Years Later
Old breaches do not expire. Criminals trade and reuse leaked databases for years after they first appear. If you used the same password from your Admission Ads account on any other website, that account remains at risk today. This kind of data fuels credential stuffing attacks, account takeovers, and identity theft. The partcularly dangerous element here is that passwords were never hashed or encrypted, making every single record immediately usable by anyone with access to the file.
How a Database Breach Works
A database breach happens when an attacker gains unauthorized access to a website or service's underlying data storage system. This can happen through unpatched software vulnerabilities, weak administrator passwords, or misconfigured servers. Once inside, attackers copy out the user database and sell or publish it online. The Admission Ads breach followed this pattern, resulting in a full dump of user credentials becoming available outside the company's control.
Check If Your Data Was Exposed
HEROIC offers a free breach scanner that searches across more than 400 billion records to tell you whether your email address appears in known data breaches. If you were an Admission Ads user or want to check any email address for exposure, visit HEROIC's free breach scanner today and find out in seconds.
Breach Breakdown
157,587 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds