Beeldenstorm-Daglicht
We noticed a concerning resurfacing of credentials originating from the now-defunct Beeldenstorm-Daglicht platform, a Dutch nonprofit arts and design workshop. The initial discovery flagged a dataset containing over 22,000 records, a significant number for a niche organization. What struck us was the dual nature of the password compromise: a substantial portion of plaintext passwords alongside MD5-hashed variants. This blend significantly lowers the barrier to entry for attackers, especially given the age of the breach and the potential for credential stuffing against other services.
The Beeldenstorm-Daglicht breach, dating back to August 26, 2018, exposed approximately 22,262 records. The compromised data primarily consists of email addresses, paired with either plaintext passwords or MD5 hashed passwords. The source structure points to a direct database compromise, with the extracted data subsequently disseminated on a prominent hacking forum. This type of leak is particularly insidious as it can be readily weaponized for credential stuffing attacks, leveraging the common practice of password reuse across multiple online platforms. The presence of plaintext passwords, even if a smaller subset, provides immediate access without the need for computational cracking, while the MD5 hashes, though weaker, are still susceptible to brute-force or rainbow table attacks given sufficient time and resources.
While this specific breach did not garner widespread mainstream media attention due to its limited scope and the organization's nature, it aligns with a broader trend of older, less secure databases from smaller organizations becoming targets for data aggregators and malicious actors. Research into similar historical breaches of non-profit or community-focused platforms often reveals similar patterns of weak password storage and subsequent public dissemination. The fact that this data is still being circulated and potentially utilized underscores the persistent threat posed by legacy data exposures.
Breach Breakdown
22,262 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds