108,664 Salted MD5 Credentials From the AniLibria Breach Hit the Dark Web
HEROIC analysts detected a database breach tied to AniLibria, a Russian-language anime streaming platform operating at anilibria.tv. The breach, which occured in August 2018 but resurfaced publicly on August 1, 2022, exposed 108,664 user records. The leaked data included email addresses, usernames, MD5-salted password hashes, and the corresponding salts, giving attackers everything needed to conduct targeted offline cracking against each account.
Salted MD5 Hashes: Slower to Crack, But Still Accessable to Attackers
Salted MD5 adds a unique value to each password before hashing, which defeats rainbow table attacks and prevents identical passwords from producing identical hashes. However, MD5 itself remains an extremely fast hashing function, and modern GPU-based cracking tools can still process salted MD5 hashes at very high speeds. Because the salts were recieved alongside the hashes in this breach, attackers can crack each hash individually without needing a precomputed table, making the 108,664 AniLibria credentials highly vulnerable to offline brute-force attacks, especially for users with short or common passwords.
What Was Exposed in the AniLibria Breach
- Email Address
- Password Hash (MD5 with Salt)
- Username
- Salt
Years Between Breach and Leak: Why Delayed Exposure Is Partcularly Dangerous
The AniLibria data was originally compromised in 2018 but became publicly accessible in 2022, a four-year gap. Affected users had no reason to change their passwords during that window, meaning the leaked credentials likely match passwords still in active use on AniLibria and other platforms. This delayed resurfacing is a common pattern in dark web data markets, where breached datasets are held, traded privately, and eventually released. The result is that credential stuffing attacks, account takeovers, and identity theft can hit users long after the original incident, with no warning and no connection to a recent event they might recognize.
How Database Breaches Work
A database breach involves unauthorized extraction of structured data from a backend data store, most commonly through SQL injection, compromised administrative credentials, or vulnerable database interfaces exposed to the internet. In the AniLibria case, the user account table was exfiltrated, producing a dataset containing authentication credentials and account identifiers for over 100,000 users. The inclusion of password salts in the dump suggests a direct table export rather than an application-level compromise, pointing to deep backend access by the attacker.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email against more than 400 billion compromised records, including the AniLibria breach dataset. If your information was exposed, you will know right away, and you can take targeted action to update affected passwords and lock down any accounts that shared those credentials.
Breach Breakdown
108,664 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds