Dark Web Intel: 10,586 CheckmarkTest Credentials Dumped on a Hacking Forum
In August 2018, HEROIC analysts identified a breach affecting CheckmarkTest, a now-defunct U.S. general business platform operating at checkmarktest.com. The incident exposed 10,586 records containing email addresses, MD5 salted password hashes, and salt values. The dataset was subsequentley posted to a prominent hacking forum, where it attracted significant attention from threat actors looking for credential material to use in automated stuffing campaigns against accounts that were never properly closed or password-rotated.
Why This Is Dangerous
When a platform shuts down, most users never think to change the password they used there -- especially if that same password was reused on banking, email, or social media accounts. The CheckmarkTest breach is particularly risky because MD5 with salting, while marginally better than unsalted MD5, is still considered weak by modern cryptographic standards. Dedicated cracking rigs can work through MD5 salted hashes at billions of guesses per second. Once the password is recovered, attackers run it against live platforms using credential stuffing tools, exploiting the fact that a large portion of people reuse passwords across sites. Dead platforms create a false sense of closure -- the data lives on long after the site is gone.
What Was Exposed
- Email addresses
- MD5 salted password hashes
- Password salt values
Why This Matters
The CheckmarkTest breach illustrates a well-documented dark web pattern: older breach datasets are repackaged into combolists and redistributed years after the original incident. When HEROIC analysts observed this dataset circulating on hacking forums, it was clear the data was being prepped for use in modern credential stuffing operations. For individuals who had accounts on checkmarktest.com, the risk is not that the site itself will be hacked again -- it no longer exists. The risk is that their email and password combination is now in active circulation among cybercriminals who will try it on every platform they can. Any user who has not changed their password on all other sites since 2018 should treat this as an unresolved security incident. It occured years ago, but its consequences are still ongoing.
How Database and Combolist Breaches Work
A database breach typically begins when an attacker discovers a vulnerability -- SQL injection, an exposed backup file, or an unsecured database port -- and uses it to download the full contents of a site's user table. The data is then cleaned, deduplicated, and formatted into a standard combolist structure: one email-password pair per line. These combolists are traded freely on hacking forums or sold in underground markets for as little as a few dollars. Seperate tools automate the process of testing each pair against popular services at high speed. When a defunct site's data reappears years later, it often means a threat actor has aquired an older copy and decided to monetize it by redistributing or deploying it in a fresh attack wave.
Check If You Are Affected
HEROIC offers a free personal data scanner that checks your email address against more than 400 billion exposed records, including defunct platform databases like CheckmarkTest. If your credentials appeared in this breach or any similar combolist release, you will be notified immediately. Run a free scan at heroic.com to find out if your data is at risk.
Breach Breakdown
10,586 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds