CardioAragon
We noticed an unusual aggregation of credentials surfacing from a Spanish medical society's online platform, CardioAragon. The discovery, made on 26-Aug-2018, revealed a significant exposure of user data, primarily email addresses and their associated password hashes. What struck us was the relatively low "pwned count" of 24,645 unique records, juxtaposed with the sensitive nature of the organization and the potential for credential stuffing attacks against its user base. The data's presence on a prominent hacking forum immediately flagged it as a high-priority incident requiring immediate analysis.
The breach of CardioAragon's platform, a society dedicated to cardiology in Spain, exposed approximately 75,000 records in total. Of these, 24,645 unique email addresses were identified, each paired with either a bcrypt or PBKDF2 hashed password. The data's origin appears to be a direct database compromise, subsequently disseminated through a popular hacking forum. This incident is significant due to the potential for these credentials to be leveraged in credential stuffing attacks, targeting not only CardioAragon's users but also any other services where they might have reused these passwords. The presence of hashed passwords, while a security measure, does not render them immune to brute-force or dictionary attacks, especially with weak password policies.
While this specific breach of CardioAragon did not generate widespread mainstream news coverage, it aligns with a broader trend observed in late 2018 and early 2019 concerning the exploitation of healthcare-related entities. Numerous smaller medical organizations and professional societies became targets, often due to less robust security postures compared to larger hospital networks. OSINT investigations at the time often pointed to the use of compromised credentials from other breaches being tested against these less secured platforms, a tactic known as credential stuffing. Research from cybersecurity firms during this period frequently highlighted the increasing sophistication of threat actors in identifying and exploiting vulnerabilities in niche online platforms, even those with seemingly limited public profiles.
Breach Breakdown
24,645 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds