BEXIMCO
We noticed an unusual spike in credential stuffing attempts originating from a specific IP range targeting several of our high-value customer accounts. Further investigation revealed that these attempts coincided with the public availability of a data dump from BEXIMCO, a prominent Bangladeshi conglomerate. What struck us as particularly concerning was the relatively low pwned count of 9,057 records, suggesting this might be a targeted leak rather than a broad sweep, potentially indicating prior intelligence gathering by threat actors.
The BEXIMCO breach, discovered on August 26, 2018, involved the compromise of their official online platform. The exposed data comprised 9,057 unique records, each containing an email address and an MD5 hashed password. This information was subsequently disseminated on a well-known cybercrime forum, classifying the incident as a database breach that contributed to a potential combolist. The use of MD5 hashing, a cryptographically weak algorithm, is a significant vulnerability, as these hashes are susceptible to brute-force attacks and rainbow table lookups, making the associated email addresses highly prone to credential stuffing and account takeover.
While this specific BEXIMCO leak did not generate widespread mainstream news coverage at the time of its discovery, it aligns with a broader trend of exposing user credentials from e-commerce and corporate platforms. Similar incidents, often involving outdated hashing algorithms, have been documented by security researchers tracking data breaches on dark web marketplaces. The availability of such combolists fuels automated attacks against other services where users may have reused credentials, underscoring the persistent threat posed by compromised credential databases.
Breach Breakdown
9,057 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds