Ambab
We noticed a new dataset appearing on a popular Telegram channel this past week, originating from an entity identified as "Ambab." What struck us immediately was the sheer volume of personally identifiable information (PII) and credential material contained within. The breach appears to be a database compromise, and the exposed data suggests a direct extraction from user account tables. The date stamp on the data, September 27, 2025, indicates a relatively recent incident, making this a high-priority investigation for our team given the potential for immediate exploitation.
The Ambab breach, discovered on September 27, 2025, involved a database compromise affecting approximately 2,300,000 records. Analysis of the leaked files revealed a comprehensive user profile dump, including 320,346 unique email addresses, corresponding usernames, first and last names, and critically, MD5 hashed and salted passwords. The presence of the salt alongside the hash is a mitigating factor, but not a guarantee against brute-force or rainbow table attacks, especially for weaker passwords. The data was subsequently disseminated through a public Telegram channel, increasing the risk of widespread access by malicious actors. The source structure points to a direct database dump, likely from a relational database management system, with minimal obfuscation or sanitization applied before exfiltration.
While specific news coverage for this particular Ambab breach is still emerging, the methodology of data exfiltration via Telegram channels is a well-documented trend in the threat landscape. Similar incidents involving the public sharing of compromised user databases have been observed across various industries, often serving as a prelude to credential stuffing attacks or further targeted phishing campaigns. Researchers have consistently highlighted the persistent threat posed by MD5 hashes, even when salted, as advancements in computational power continue to erode their security margins. The fact that Ambab is an India-based IT services platform suggests potential downstream impacts for their client base, depending on the nature of their service delivery and data handling practices.
Breach Breakdown
320,346 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds