Bio et Bien-Etre
We noticed an unusual spike in credential stuffing attempts targeting a subset of our user base, prompting an investigation into potential data exposure events. What struck us was the consistent pattern of compromised credentials originating from a specific, older breach that had not previously been flagged as impacting our organization. This particular incident, dating back to August 2018, involved a French directory and guide focused on organic and sustainable living, Bio et Bien-Etre. The fact that this data, particularly the inclusion of plaintext passwords, is still being actively leveraged years later underscores the persistent threat posed by legacy credential exposure.
The Bio et Bien-Etre breach, discovered on August 26, 2018, exposed approximately 15,662 records. The leaked data types are particularly concerning, encompassing Email Addresses, Plaintext Passwords, and Password Hashes (specifically MD5). This indicates a significant vulnerability where sensitive user credentials were not adequately protected. The data surfaced on a prominent hacking forum, suggesting its availability to a wide range of malicious actors. The nature of the leak suggests a direct database compromise rather than a more sophisticated supply chain attack, and its subsequent use in credential stuffing operations confirms its classification as a potential combolist source.
While this specific breach may not have garnered widespread mainstream news coverage at the time of its discovery, its continued relevance highlights a common cybersecurity challenge. The reuse of passwords across different platforms means that even seemingly obscure or older breaches can become vectors for future attacks. Organizations like ours must remain vigilant in monitoring for the reappearance of previously compromised credentials in new attack campaigns. Research consistently shows that MD5 hashes, while considered weak, are still readily crackable with modern computing power, especially when paired with common password patterns often found in such breaches.
Breach Breakdown
15,662 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds