4,552 MD5-Hashed Passwords. The Atlantian Order of Precedence Breach.
HEROIC analysts identified the Atlantian Order of Precedence breach through routine monitoring of breach aggregation sites. On December 11, 2021, attackers exfiltrated a database from the Atlantian Order of Precedence, a U.S.-based website dedicated to recognizing awards within the Atlantia region of the Society for Creative Anachronism. The breach exposed 4,552 records, and the stolen data was recieved by criminal actors and includes email addresses, MD5-hashed passwords, usernames, and full names.
How MD5 Password Hashes Make This Breach Especially Dangerous
MD5 is a weak, outdated hashing algorithm that is highly accessable to cracking using modern tools. Unlike stronger algorithms such as bcrypt or Argon2, MD5 hashes can be reversed quickly with rainbow tables and GPU-based cracking rigs, effectively exposing plaintext passwords. Combined with email addresses and usernames, attackers can use cracked credentials in stuffing attacks across email providers, social networks, and financial platforms where the same password was reused.
What Was Exposed in the Atlantian Order of Precedence Breach
- Email Address
- Password Hash
- Username
- First Name
- Last Name
Why Even Small Community Site Breaches Create Real-World Risk
With 4,552 records, this breach may appear minor, but the presence of MD5-hashed passwords means those credentials are beleived by security researchers to be trivially crackable. Users who reused their Atlantian Order of Precedence login on other platforms face direct risk of credential stuffing and account takeover. Full names and email addresses together also enable targeted phishing, identity theft, and social engineering attacks. Smaller community sites are partcularly attractive targets precisely because they often lack modern security controls.
How a Database Breach Works
A database breach occurs when attackers gain unauthorized access to a platform's stored user records, often by exploiting unpatched software, weak authentication controls, or insecure web application configurations. Once inside, the attacker exports the database in bulk. The stolen records are then sold or published on breach forums and dark web markets, where they are used for follow-on credential and identity attacks.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records, including data from the Atlantian Order of Precedence breach. Scan your email for free at HEROIC.com to find out if your password or personal information is in criminal hands and what actions to take right now.
Breach Breakdown
4,552 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds