BRASSART Data Breach: 3,565 MD5-Hashed Passwords Exposed
HEROIC analysts identified a dataset tied to BRASSART, a French private higher-education school for art, circulating on a cybercrime forum. The breach dates back to August 26, 2018, and exposed 3,565 records made up of email addresses paired with MD5 hashed passwords.
Why This Is Dangerous
MD5 is a decades-old hashing algorithm that's now considered weak by modern security standards. Attackers can crack large batches of MD5 hashes quickly using widely available cracking tools and precomputed lookup tables, especially for passwords that aren't particularly long or complex. That means the protection this hashing offered was minimal, and many of these passwords have likely already been converted back into plain, usable text.
What Was Exposed
- Email addresses of BRASSART students and staff
- Password hashes, secured with the outdated MD5 algorithm
Why This Matters
Once cracked, these credentials become just as dangerous as a plaintext leak. Attackers fold cracked passwords into combolists and test them against email providers, banking sites, and other platforms, hoping that someone reused their BRASSART login elsewhere. Given that students often use the same password across school accounts, personal email, and social media, a breach like this can quickly cascade into account takeover, identity theft, and financial fraud well beyond the original school system.
How Database and Combolist Breaches Work
This breach traces back to a direct database compromise, where an attacker extracted BRASSART's stored user records, including the MD5 hashed passwords, straight from its systems. Because MD5 offers weak protection, the stolen data didn't stay locked away for long. It surfaced on a cybercrime forum, where records like these commonly get merged with data from unrelated breaches into combolists, giant files of email and password pairs used to automate credential stuffing attacks across the internet.
Check If You Are Affected
You can check whether your email address appears in this breach or any other using HEROIC's free breach scanner, which searches a database of more than 400 billion leaked and breached records. If you're affected, change that password immediately anywhere you may have reused it, and consider using a password manager to keep every account's credentials unique.
Breach Breakdown
3,565 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds