Alabrent
We noticed the reappearance of a dataset originating from Alabrent, a Spanish trade publication, on a well-known hacking forum. This particular breach, initially documented in August 2018, has resurfaced, presenting a renewed risk to its user base. What struck us as particularly concerning is the continued availability of plaintext passwords, a vulnerability that has only amplified with time and the proliferation of credential stuffing attacks. The dataset, impacting 10,114 individuals, underscores the persistent threat posed by older, unaddressed vulnerabilities.
The Alabrent breach, discovered on August 21, 2018, involved a direct database compromise. Threat actors successfully exfiltrated 10,114 records, primarily consisting of email addresses and plaintext passwords. The source structure points to a direct database dump, likely obtained through SQL injection or compromised credentials. The leak locations have historically been various underground forums and marketplaces, with this particular instance being observed on a prominent English-language hacking forum. The significance of this breach lies not only in the volume of exposed credentials but also in the sensitive nature of the data, given Alabrent's industry focus on B2B communications and potentially proprietary business information shared by its readership.
While there was no widespread news coverage at the time of the initial leak in 2018, the reappearance of such datasets is a common phenomenon in the OSINT landscape. Security researchers frequently track these forums for emerging or re-emerging data dumps. The presence of plaintext passwords is a recurring theme in many breaches from this era, highlighting a broader industry-wide issue with password security practices that has been extensively documented by organizations like Troy Hunt's "Have I Been Pwned," which lists Alabrent as a confirmed breach.
We observed a significant data leak originating from 'MyFreeMP3,' a Russian music streaming and download service. The breach, discovered on 20-Jan-2019, exposed a substantial volume of user data, raising concerns about the privacy and security of its user base. What immediately stood out was the sheer scale of the compromise, affecting over 25 million accounts, and the inclusion of sensitive personal identifiers alongside credentials. The continued availability of such large-scale datasets on public forums presents a persistent threat vector for identity theft and targeted phishing campaigns.
The MyFreeMP3 breach, identified on January 20, 2019, appears to be a direct database exfiltration. Threat actors gained access to approximately 25,132,638 records. The compromised data includes a wide array of personal information, such as email addresses, usernames, MD5-hashed passwords, IP addresses, and user agent strings. The source structure suggests a primary database compromise, potentially through exploitation of a web application vulnerability or compromised administrative access. The leak locations have been identified across multiple underground forums and file-sharing platforms, with recent observations pointing to continued distribution on a prominent Russian-language hacking forum. The implications are far-reaching, given the potential for these hashed passwords to be cracked and reused on other services, and the detailed user profiling enabled by the additional personal identifiers.
This breach garnered some attention within the cybersecurity community at the time of its discovery. Reports from security researchers and forums indicated the widespread distribution of the MyFreeMP3 dataset. While not reaching mainstream news outlets, its presence on multiple hacking forums and its substantial size made it a notable event for those monitoring data leaks. The use of MD5 hashing for passwords, while common at the time, is now considered an outdated and insecure practice, a point frequently raised in discussions surrounding such older breaches and their continued relevance.
Our analysis has identified a recent leak associated with 'GamerNexus,' a prominent technology review website. The dataset, discovered on 05-May-2023, impacts a considerable number of users, raising immediate concerns about the integrity of their personal information. What is particularly noteworthy is the combination of forum credentials with forum activity logs, suggesting a breach that goes beyond simple account enumeration and delves into user behavior and engagement patterns. The continued exposure of such detailed user data from a community-focused platform presents a significant risk for social engineering and targeted harassment.
The GamerNexus breach, first observed on May 5, 2023, appears to be a comprehensive compromise of their forum database. The leaked data affects 57,342 users and includes usernames, email addresses, IP addresses, forum post content, and timestamps of activity. The source structure indicates a direct dump of the forum's user and post databases. The leak locations have been primarily observed on private Discord servers and specific niche hacking forums, suggesting a more targeted distribution than a broad public release. The significance of this breach lies in the potential for threat actors to leverage forum post content for highly personalized phishing attacks or to identify individuals based on their expressed interests and online interactions within the community.
While this breach has not generated widespread mainstream media coverage, it has been discussed within specialized cybersecurity forums and communities focused on gaming and tech. OSINT investigations have confirmed the authenticity of the leaked data. The inclusion of forum post content is a less common but highly valuable piece of information for attackers, as it moves beyond static personal identifiers to dynamic user expression, a tactic often employed in advanced persistent threats (APTs) and sophisticated social engineering operations. This type of data can be cross-referenced with other leaked datasets to build richer user profiles.
Breach Breakdown
10,114 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds