The AME Awards Breach Happened in 2018. The Data Just Keeps Circulating.
HEROIC analysts confirmed the AME Awards breach occured in August 2018. At that time, nearly 98,881 user records were exposed from this now-defunct US-based advertising and marketing information website. The data went public shortly after and has been recieved by threat actor communities ever since, making credentials that were compromised years ago still actionable in today's credential stuffing campaigns.
What Attackers Can Do With Nearly 100,000 Plaintext Credentials
Plaintext passwords require zero effort to exploit. Attackers take the leaked email and password combinations from a breach like AME Awards and run them through automated tools that test those credentials against hundreds of other platforms simultaneously. Banking portals, email accounts, social media platforms, and subscription services are all tested in bulk. Even if only a small percentage of users reused their password, that still translates to thousands of accounts accessable without any additional hacking required.
What Was Exposed in the AME Awards Breach
- Email Address
- Plaintext Password
The AME Awards Breach Happened in 2018. The Data Is Still Circulating.
The AME Awards breach is a clear example of why breach data does not become harmless with age. These records have been seperate from the original platform for years, folded into combo lists traded across criminal forums and used in ongoing credential stuffing operations. Users who registered on AME Awards and have not changed their passwords on any other platform where they reused those credentials remain at risk of account takeover, identity theft, and financial fraud. The long tail of breach exposure is one of the most underestimated risks in credential security.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to an organization's backend database, typically by exploiting vulnerabilities such as SQL injection, weak admin credentials, or misconfigured cloud storage. Once inside, the attacker exports user records in bulk. When passwords are stored in plaintext rather than being hashed with a strong algorithm, the stolen credentials are immediately ready to use across the internet with no additional processing required.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email against more than 400 billion compromised records, including data from the AME Awards breach. Run your free scan at HEROIC to find out if your credentials were exposed, and take steps to secure your accounts before someone else does.
Breach Breakdown
98,881 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds