Inside the Charsur Arts Foundation Breach: How 7,107 Indian Accounts Were Exposed
In August 2018, HEROIC analysts identified a breach affecting Charsur Arts Foundation, an Indian arts and culture organization based at charsur.com. The incident, which surfaced publicly on August 26, 2018, exposed 7,107 records containing email addresses and MD5 hashed passwords. The dataset was subsequently posted to a popular hacking forum, where it continued to circulate and recieve renewed attention from threat actors years after it first appeared.
Why This Is Dangerous
MD5 password hashes are considered cryptographically weak by modern standards. Unlike stronger hashing algorithms, MD5 can be reversed through precomputed lookup tables known as rainbow tables, meaning attackers do not need significant computing power to recover original passwords. When a site like Charsur Arts Foundation is breached, the real danger is not just the loss of that one account -- it is credential stuffing. Attackers take the recovered email and password combinations and try them automatically across banking platforms, email providers, and social media. Users who reuse passwords across sites are particulary vulnerable to this type of attack.
What Was Exposed
- Email addresses
- MD5 hashed passwords
Why This Matters
Breaches from 2018 are not ancient history -- they are active threats. The Charsur Arts Foundation dataset resurfaced on underground forums years after the original incident, compiled into combolists and traded among new threat actors who were not involved in the original breach. For affected users, this means the window of risk never really closed. Anyone who used the same email and password combination on charsur.com and has not since changed their credentials on other platforms may still be at risk of account compromise today. Organizations operating in the arts and culture sector, which often have smaller security teams, should treat older breaches as ongoing incidents rather than closed cases. The fact that this data occured in a Hindi-language environment also suggests the impacted users may not have recieved timely breach notifications.
How Database Breaches Work
A database breach of this type typically occurs when an attacker exploits a vulnerability in a web application -- such as SQL injection or an exposed admin panel -- to extract the underlying user database. The attacker downloads the full table of user records, which in this case included email addresses and hashed passwords. The extracted data is then shared or sold on hacking forums, where other criminals use it for credential stuffing campaigns, phishing, or resale. MD5 hashing was common practice for password storage in the early 2010s, but it provides very little protection against modern cracking tools. Sites still using MD5 for passwords in 2018 were already behind industry standards by several years.
Check If You Are Affected
HEROIC offers a free personal data scanner that checks your email address against more than 400 billion exposed records, including breach databases like the Charsur Arts Foundation dump. If your credentials appeared in this breach or any similar incident, you will be notified immediately. Run a free scan at heroic.com to find out if your data is at risk.
Breach Breakdown
7,107 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds