The Aguapen Breach Left 6,884 Ecuadorian Water Customers Exposed to Account Takeover
When a public water utility gets breached, the danger is not just inconvenience. Aguapen, Ecuador's state-owned water company, had 6,884 customer records stolen in October 2024 and stored passwords using MD5, a hashing algorithm so thoroughly broken that attackers can reverse most hashes in seconds using freely available tools. Every affected customer faces a direct and immediate path from this breach to account takeover on any other site where they reused that password.
Why This Is Dangerous
MD5 is not encryption. It is a one-way hash, but rainbow tables and GPU cracking rigs have made MD5 functionally equivalent to storing passwords in plaintext. An attacker who downloads this breach file can run the hashes through a cracking tool and recover the majority of real passwords within hours. Those passwords are then tested against Gmail, banking apps, and social media at scale. Victims never receive a warning. The first sign is usually a locked account or an unauthorized transaction.
What Was Exposed
- First Name and Last Name
- Phone Number
- Password Hash (MD5 format)
Why This Matters
The combination of real names, phone numbers, and crackable passwords creates a complete toolkit for multiple attack chains:
- Credential stuffing: Recovered passwords are automatically tested across hundreds of other platforms.
- Account takeover: Email, banking, and social accounts using the same password are immediately at risk.
- SIM-swapping: A name plus phone number is often enough to trick a mobile carrier into transferring a phone number to an attacker-controlled SIM, bypassing SMS-based two-factor authentication.
- Targeted phishing: A phone call or SMS to a named individual, referencing their real utility account, is far more convincing than a generic scam.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to the backend database of an application or service. Common entry points include SQL injection vulnerabilities, compromised administrative credentials, or unpatched server software. Once inside, the attacker exports the contents of user tables, typically including everything stored about each account: names, contact details, and password hashes. The data is then either sold on dark web forums, used directly for credential attacks, or both.
Check If You Are Affected
Heroic's breach search engine indexes over 400 billion compromised records, including data from breaches like Aguapen. If you had an account with Aguapen or shared your email or phone number with them, search now to see if your information is in the database.
Breach Breakdown
6,884 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds