The Calling Software Breach Gave Hackers Usernames, Emails and Full Names to Exploit
In April 2022, Calling Software, a US-based online calling platform, had its user database exposed in a breach that recieved limited attention due to its small scale. But for the 806 users whose full names, email addresses, usernames, and password hashes were leaked, the risk is real. Smaller breaches from niche platforms are often overlooked, while the data quietly circulates in credential stuffing circles for years.
What Attackers Can Do With This Data
Attackers with access to this dataset can attempt to crack the bcrypt password hashes using brute force, cross-reference the exposed email addresses with credentials from larger breaches, and use the full names and usernames to craft highly personalized phishing emails. Calling software platforms often integrate with business communication systems, making this breach a potential stepping stone to a much larger organizational compromise. The value of this data is partcularly high for targeted attacks against business users.
What Was Exposed in the Calling Software Breach
- Email Address
- Password Hash (bcrypt)
- Username
- First Name
- Last Name
Why This Breach Puts You at Real Risk
Even bcrypt-hashed passwords are not fully safe if users chose weak or commonly used passwords. Attackers run the hashes through optimized cracking tools and wordlists built from previous breach data. With a full name, username, and email address also available, an attacker can build a convincing impersonation or launch a spear-phishing attack that beleives to come from a known contact. If you reused your Calling Software password, those other accounts are now at risk.
How a Database Breach Works
A database breach occurs when unauthorized parties access a company's backend data store, typically by exploiting a software vulnerability, a misconfigured server, or compromised administrator credentials. Once access is gained, the full user table can be exported in seconds. The resulting database dump is then shared on hacking forums and Telegram channels, where it gets used in credential stuffing attacks and sold to other threat actors over an extended period.
Check If Your Data Was Exposed
HEROIC's dark web monitoring database contains over 400 billion exposed records, including data from breaches like Calling Software. Run a free scan to see if your email address, username, or full name appears in this or thousands of other known breaches. Early detection is the most effective way to protect your accounts before attackers can act on the exposed data.
Breach Breakdown
806 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds