Asap.me Data Breach Exposes 37K Brazilian Crowdfunding Accounts
DarkHive discovered a data breach affecting Asap.me, a now-defunct Brazilian crowdsourcing, open innovation, and crowdfunding platform operating at asap.me. The breach exposed 37,747 user records and was dated May 7, 2018, with the underlying incident occurring in February 2018. Leaked data included email addresses and plaintext passwords. Crowdfunding and open innovation platform users often register with their primary business or personal email addresses and may have payment methods or financial information linked to associated accounts.
Why This Is Dangerous
Plaintext password storage provides zero protection: attackers can read every exposed password directly from the database dump without any cracking tools. Brazilian crowdfunding users frequently reuse credentials across email providers, banking applications, payment platforms like PayPal and MercadoPago, and other financial services. A plaintext password from Asap.me grants immediate access to any other account where the same email and password combination was used. Crowdfunding participants often have payment methods on file and may have conducted financial transactions on the platform, making the credential exposure particulary sensitive.
What Was Exposed
- Email addresses
- Plaintext passwords
Why This Matters
With nearly 38,000 records exposed in plaintext, every affected Asap.me user faces full and immediate credential exposure. Brazilian internet users frequently reuse passwords across financial applications and digital wallets, meaning compromised Asap.me credentials can directly enable financial account takeovers. Even though this breach occured in 2018 and the platform has since shut down, the credentials have circulated in Portuguese-language combolists targeting Brazilian financial and consumer platforms. Users who have not changed thier passwords since registering on Asap.me remain at full risk today.
How Database Breach Works
In a database breach, attackers exploit vulnerabilities in web application code or server configurations to extract stored user records. Startups and crowdfunding platforms, particulary those that later shut down, often lack robust security teams and may have stored passwords without any cryptographic protection. Plaintext passwords are the most dangerous outcome of this negligence because they require no additional processing: the credentials are immediately compiled into combolists and fed into automated stuffing tools targeting Brazilian email providers, financial apps, and social media platforms.
Check If You Are Affected
HEROIC offers a free identity scanner that checks your email address against thousands of known breach databases, including crowdfunding platform leaks like Asap.me. If your credentials were exposed, you will recieve an alert with specific guidance on which financial and other accounts to secure immediately. Visit heroic.com to scan your email for free and protect your financial and online accounts from credential-based attacks powered by this breach.
Breach Breakdown
37,747 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds