Catching Features
We noticed a recent resurgence of interest in a dataset originating from a 2018 incident involving "Catching Features," a U.S.-based 3D orienteering simulation and training tool. The data, initially surfaced on a prominent hacking forum, has reappeared in discussions and is being repurposed. What struck us was not the novelty of the breach itself, but its continued relevance in credential stuffing campaigns, underscoring the enduring risk posed by even older, seemingly niche data exposures. The relatively small number of affected accounts, 5,503, belies the potential impact when aggregated with other compromised datasets.
The "Catching Features" breach, discovered on August 26, 2018, stemmed from a database compromise. The exposed information comprised 5,503 records, each containing an email address and a plaintext password. This direct exposure of credentials in clear text is a critical vulnerability, bypassing the need for any further exploitation of the service itself. The threat theme here is straightforward: credential stuffing. Attackers leverage these leaked username-password pairs to attempt logins on other popular online services, capitalizing on users' tendency to reuse credentials across multiple platforms. The source structure indicates a direct database dump, meaning no complex exfiltration techniques were necessarily employed by the initial threat actor.
While this specific breach did not garner significant mainstream news coverage at the time of its discovery, its reappearance on hacking forums and its inclusion in larger, aggregated credential stuffing lists by threat intelligence providers are notable. Open-source intelligence (OSINT) indicates that "Catching Features" was a niche but established tool within its specific community. The fact that this data, over five years old, remains a viable component in active attack chains highlights a persistent challenge in enterprise security: the long tail of data breach impact.
We observed a concerning trend involving a dataset associated with "TechSmith Corporation," a provider of screen recording and video editing software. While the initial discovery date is listed as 2014, recent activity suggests this data is being actively circulated and utilized by malicious actors. What is particularly striking is the nature of the leaked information – primarily email addresses and hashed passwords – and the sheer volume of records involved, indicating a significant compromise of user accounts. The longevity of this data's utility in current threat landscapes is a testament to the efficacy of certain attack vectors.
The "TechSmith Corporation" breach, initially reported in 2014, involved a substantial exposure of user data. The compromised dataset contained approximately 12.5 million records, primarily consisting of email addresses and hashed passwords. While the passwords were not in plaintext, the use of relatively weak hashing algorithms in 2014 means many of these hashes could be cracked with modern computing power and readily available cracking tools. The threat theme here revolves around both credential stuffing and the potential for account takeover. The source structure points to a database breach, likely involving SQL injection or similar vulnerabilities that allowed for bulk data extraction. The leak locations were initially reported on underground forums, and the data has since been integrated into various breach databases used by attackers.
At the time of its discovery in 2014, the TechSmith breach received some media attention, particularly within the cybersecurity community, due to the scale of the exposure. References can be found in early reports from cybersecurity news outlets and in historical breach databases. More recent OSINT suggests that this dataset is frequently referenced in discussions related to credential stuffing toolkits and is often included in lists of compromised credentials used by phishing and malware campaigns. The continued relevance of this decade-old breach underscores the persistent challenge of managing and mitigating the impact of historical data exposures.
Our attention was drawn to a recent spike in activity surrounding a dataset linked to "MyFitnessPal," a popular health and fitness tracking application. While the primary breach occurred in 2018, the data's reappearance in new contexts, particularly its integration into sophisticated phishing operations, is noteworthy. What stands out is the combination of user-provided personal information with account credentials, creating a rich profile for targeted attacks. The sheer volume of affected users, coupled with the sensitive nature of the data, makes this a persistent concern for both individuals and organizations whose employees might use such services.
The "MyFitnessPal" breach, first publicly disclosed in March 2018, resulted from a sophisticated cyberattack that compromised user account information. The incident exposed data for approximately 150 million users. The leaked data types included email addresses, usernames, and hashed passwords. Crucially, for a subset of users, more sensitive information was also exposed, including details on diets, exercise, and macronutrient intake. The threat theme here is multifaceted: credential stuffing using the compromised email/username and hashed password pairs, alongside highly targeted social engineering and phishing attacks leveraging the detailed personal health information. The source structure indicates a targeted intrusion into their backend systems, allowing for the exfiltration of a significant portion of their user database. Leak locations were initially reported on underground forums, and the data has since been widely distributed and incorporated into various threat intelligence feeds.
The MyFitnessPal breach garnered significant media attention globally in 2018, with extensive coverage from major news outlets and cybersecurity publications. Numerous articles detailed the scope of the breach and advised users on protective measures. OSINT confirms that the dataset has been a staple in threat actor toolkits since its exposure. Researchers have also published analyses detailing how this data has been used in subsequent phishing campaigns and account takeover attempts, highlighting the long-term impact of such large-scale personal data exposures. The continued availability and use of this data serve as a stark reminder of the enduring value of personal information in the cybercriminal ecosystem.
Breach Breakdown
5,503 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds