Carnegie Greenaway: 7,819 Stolen Login Credentials Hit the Dark Web
HEROIC analysts identified a data breach at Carnegie Greenaway, the official platform for The CILIP Carnegie and Kate Greenaway Medals -- a prestigious UK non-profit organisation running annual book awards for children and young adult literature. The breach occured in July 2018 and exposed 7,819 unique email addresses paired with plaintext passwords drawn from over 15,000 total records. The data was subsequently shared on a prominent hacking forum, where it entered active circulation among credential stuffing operators. Despite the breach date, this dataset remains dangerous: plaintext passwords from 2018 are still viable against users who have not changed them or who reuse the same credentials on other platforms.
Why the Carnegie Greenaway Breach Is Still Dangerous in 2025
Breaches from 2018 are not ancient history for cybercriminals. Credential stuffing operations routinely recieve datasets that are years old, cycling through them against banking sites, email providers, and e-commerce platforms on the assumption that a meaningful percentage of victims have never changed their passwords. The Carnegie Greenaway breach is a textbook example: plaintext passwords require no cracking, and users who registered with a literary awards site may have used a memorable password they also use elsewhere. The longer this data circulates without users taking action, the more attacks it enables.
What Was Exposed in the Carnegie Greenaway Breach
- Email Addresses (7,819 unique)
- Plaintext Passwords
Why This Matters Beyond the Numbers
Non-profit and cultural organisation breaches are frequently underreported and underprioritized by affected users, who may not consider a book awards site a high-value target. But credential reuse means the stakes are far higher than the site itself. An email address and password from carnegiegreenaway.org.uk could unlock an email inbox, a bank account, or a corporate VPN -- each a seperate high-value target that has nothing to do with children's literature. The hacking forum posting confirms this data was shared broadly and is likely integrated into credential stuffing databases that remain in active use today.
How Database Breaches Work
Database breaches at non-profit and membership-based platforms often result from outdated software, unpatched content management systems, or weakly protected administrative portals. In Carnegie Greenaway's case, the breach produced a direct dump of user records including passwords stored in plaintext -- a significant security failing that indicates no password hashing was implemented at the time of the breach. Once the database was extracted, the attacker uploaded it to a hacking forum where it was indexed and archived by multiple parties. Datasets posted to prominent forums rarely disappear; they migrate across platforms and merge into larger combolists that fuel credential attacks for years.
Check If You Are Affected by the Carnegie Greenaway Breach
HEROIC's free breach scanner searches more than 400 billion records, including the Carnegie Greenaway dataset. If you ever registered on carnegiegreenaway.org.uk or used that email address and password combination on any other site, enter your email now to check your exposure. Because the passwords in this breach were stored and leaked in plaintext, any site where you reused those credentials should be treated as compromised until the password is changed.
Breach Breakdown
7,819 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds