Chris Wilson
We've observed a consistent pattern of older, smaller breaches resurfacing in combolists and forum posts, often years after the initial incident. These "legacy" breaches can still pose a risk, especially if users have reused passwords across multiple accounts. Our team recently identified one such instance: a breach from **Chris Wilson Artist**, an online portfolio site, dating back to **August 2018**. What really struck us wasn't the relatively low volume of records, but the presence of plaintext passwords alongside hashed credentials, which significantly increases the risk of credential stuffing attacks.
Chris Wilson Artist: 12k Records Resurface with Plaintext Passwords
In **August 2018**, the online portfolio site **chriswilsonartist.com**, belonging to artist **Chris Wilson**, suffered a data breach. The breach, affecting approximately **12,000** unique records, has recently resurfaced on a popular hacking forum. The combination of email addresses and plaintext passwords presents a significant risk, even years after the initial breach.
The breach was initially reported in **August 2018** after the dataset appeared on a hacking forum. The presence of both plaintext passwords and PHPass hashed passwords caught our attention, as it suggests either a misconfiguration or a vulnerability that allowed attackers to obtain passwords in an unencrypted format. This combination makes the exposed credentials highly valuable for attackers looking to compromise other user accounts.
This breach matters to enterprises now because it highlights the long tail of security risk. Even seemingly minor breaches from years ago can still provide attackers with valuable credentials for use in credential stuffing attacks against more valuable targets. The reuse of passwords across personal and work accounts is a persistent problem, and older breaches like this one can serve as a source of credentials for compromising corporate assets.
- Total records exposed: 11,880
- Types of data included: Email Address, Plaintext Password, PHPass hashed passwords
- Source structure: Database dump, subsequently posted on a hacking forum.
- Leak location(s): Popular hacking forum.
- Date of first appearance: August 26, 2018
While this specific breach hasn't received widespread media attention, the phenomenon of older breaches resurfacing is well-documented. Security researchers have noted the persistence of data dumps on hacking forums and the use of combolists derived from these breaches in automated attacks. The appearance of plaintext passwords in this breach underscores the importance of proper password storage practices and the need for users to adopt unique, strong passwords for all their online accounts.
Breach Breakdown
11,880 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds