The Choco.ci Breach Put 37,686 Stolen Email and Password Pairs Online in 2018
HEROIC's threat intelligence team identified the Choco.ci breach while monitoring a hacking forum for West African media and news platforms. In July 2018, the database for Choco.ci, an online news platform operated from Ivory Coast at choco.educarriere.ci, was extracted and posted publicly. The breach exposed 37,686 user records, including email addresses and passwords stored in plaintext. No encryption, no hashing, no protective layer of any kind separated the raw passwords from anyone who downloaded the file. The dataset was later shared across multiple forums and incorporated into credential combolists, where it continues to circulate. Most affected users were never notified that their data was exposed, and many likely still use the same email and password combination on other platforms today.
Why the Choco.ci Breach Is Dangerous
Plaintext password storage is a fundamental security failure that turns any breach into an immediate threat. When passwords are stored without hashing or encryption, attackers do not need to do any additional work after downloading the database. Every credential in the Choco.ci dataset was ready to use the moment the file appeared on the forum. News platforms attract readers who often register casually using their primary email address and a commonly reused password. That combination makes this breach particularly useful for credential stuffing campaigns, where automated tools test each email and password pair against banking sites, email providers, streaming services, and e-commerce platforms. If a Choco.ci user reused their password anywhere else, those accounts became vulnerable the same day the breach was posted.
What Was Exposed
- Email addresses
- Plaintext passwords (unencrypted, immediately usable)
Why This Matters
Nearly 38,000 exposed records from a regional news platform may seem minor compared to large corporate breaches, but the impact on individual users is identical. Credential stuffing attacks do not care about the size or prestige of the source database. They care about whether the email and password combination works somewhere else. HEROIC analysts have observed the Choco.ci dataset appearing in aggregated combolists compiled from dozens of smaller breaches, which means the reach of this data extends far beyond the original forum post. These aggregated combolists are some of the most widely distributed files on dark web markets, and they are actively maintained and updated. The risk from this breach did not dissapear in 2018. It has been compounding ever since as the data gets repackaged and redistributed to new threat actors who test it against new targets.
How a Database Combolist Breach Works
A database combolist breach begins when an attacker gains unauthorized access to a platform's backend, typically through a SQL injection vulnerability or an exposed database configuration file. The attacker extracts the user table and posts the raw credential data to a hacking forum. Other threat actors download the file and feed it into automated credential stuffing tools that systematically test each email and password combination across hundreds of websites. The proccess requires minimal effort on the attacker's part and can run at scale overnight. In the Choco.ci case, the dataset was later incorporated into larger combolist collections, meaning it has been tested against far more targets than the original attacker likely attempted.
Check If You Are Affected
HEROIC offers a free dark web scanner that checks your email against more than 400 billion exposed records, including this Choco.ci dataset. If your email address appeared in this breach or any related combolist, you will know immediately. Run your email through HEROIC's free scanner, review the results, and change any password that matches what you used on Choco.ci. Even if you seperate your online accounts by using different passwords, it is worth confirming that this breach did not catch you using a shared credential.
Breach Breakdown
37,686 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds