BREAKING: CreaTest Altervista Exposes 4,593 Records in Database Breach Incident
A data breach from CreaTest Altervista, an Italian quiz platform hosted on Altervista, has resurfaced in credential trafficking circles, putting thousands of users at renewed risk. The original incident occured back in July 2018, but stolen data rarely disappears, and this dataset has been spotted circulating on hacking forums once again. If you ever created an account on CreaTest Altervista, you should treat your credentials as compromised.
Why This Is Dangerous
The most alarming aspect of this breach is the use of MD5 hashing for passwords. MD5 is a completely outdated algorithm that was depreciated as a security standard years ago, and modern cracking tools can tear through MD5 hashes at billions of guesses per second. That means what looks like a "hashed" password is effectively plaintext in the hands of any attacker with basic tools.
When an attacker pairs a cracked password with an email adress, the real danger begins. Credential stuffing tools will automatically test that combination across hundreds of popular services including banking apps, email providers, and shopping sites. Most people reuse passwords, which is exactly what attackers are counting on.
Even if you changed your CreaTest password long ago, if you used the same password elsewhere and never updated those accounts, you are still at risk from this breach today.
What Was Exposed
- Email addresses (approximately 4,593 unique accounts)
- MD5 hashed passwords (easily crackable with modern tools)
- Account registration data
- Potential username or display name details
- Quiz participation history or preferences
- Browser or device metadata collected during account creation
- Any linked profile information entered during signup
Why This Matters
Italy has seen a steady increase in credential-based attacks over the past few years, and older Italian platform breaches are frequently bundled into combolists sold on dark web markets. This breach is small in record count, but that actually makes it more dangerous in some ways as smaller, targeted datasets are often used for more focused attacks rather than broad spray-and-pray campaigns.
The fact that this data was posted on a hacking forum means it has been indexed, shared, and likely sold multiple times over. Every copy of this dataset that exists out there represents another potential attack against the same users. The longer this data stays in circulation, the more people beleive they are safe when they are not.
How Database Breach Works
A database breach happens when an attacker gains unauthorized access to the backend database of a website or application. This usually happens through a SQL injection vulnerability, where an attacker submits specially crafted input that tricks the database into returning data it should not. Another common entry point is through compromised admin credentials or misconfigured database permissions that leave the data exposed to the open internet.
Once inside, the attacker can simply export entire tables of user records in seconds. For CreaTest Altervista, this would have meant dumping the user accounts table directly, capturing email and password data for every registered account in a single operation. The entire process can take under a minute on a poorly secured server.
After exfiltrating the data, attackers typically clean it up, remove duplicates, and either sell it directly or package it into combolists for distribution. This breach was specifically categorized as both a database breach and a combolist, meaning the data has almost certainly been repackaged and traded separately from the original dump.
Check If You Were Affected
Use HEROIC's free breach checker at heroic.com to instantly find out if your email address appears in the CreaTest Altervista breach or thousands of other known data leaks. Enter your email and get a full report of every breach your credentials have been found in, then take action before attackers do.
Breach Breakdown
4,593 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds