Agape International Spiritual Center
We noticed a significant data exposure event impacting the Agape International Spiritual Center, a prominent United States-based spiritual community platform. The discovery, made on August 26, 2018, revealed a dataset containing approximately 29,000 records originating from their online services and programs. What struck us as particularly concerning was the nature of the exposed credentials, which included a mix of MD5 and phpBB hashed passwords, alongside email addresses. This combination presents a clear vector for credential stuffing attacks and further compromise of user accounts.
The breach breakdown indicates a database compromise, likely resulting from a vulnerability that allowed unauthorized access to user information. Approximately 27,809 unique email addresses were exfiltrated, paired with their corresponding password hashes. The hashing algorithms employed, MD5 and phpBB's default, are considered weak by modern cryptographic standards, making them susceptible to offline brute-force or dictionary attacks. This data was subsequently posted on a well-known hacking forum, suggesting the threat actors intended to monetize or distribute the compromised credentials. The source structure points to a direct database extraction, rather than a more complex supply chain attack, simplifying the initial vector analysis.
While direct news coverage of this specific breach in 2018 was limited, the nature of the exposed data aligns with common threat themes observed during that period. The use of weak hashing algorithms by organizations was a recurring vulnerability exploited by attackers. The posting of such datasets on public forums is a well-documented OSINT indicator of compromised credentials, often forming the basis of larger, multi-site credential stuffing campaigns. Research from cybersecurity firms at the time frequently highlighted the risks associated with MD5 hashing and the prevalence of leaked password databases being traded on the dark web.
Breach Breakdown
27,809 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds