ClickitGolf Breach: 58,951 U.S. Golf News Platform Users’ Credentials Exposed
HEROIC's DarkHive intelligence system discovered the ClickitGolf data breach, exposing 58,951 records. The breach occured in August 2018, affecting users of this U.S.-based golf news and sports information platform. Leaked data includes email addresses and plaintext passwords, meaning every affected user's credentials were stored without any protection and are immediately usable by attackers without any cracking required.
Why This Is Dangerous
Plaintext password storage is the most severe credential security failure possible. ClickitGolf's 58,951 exposed U.S. golf community accounts give attackers a ready-to-use list of email and password pairs requiring zero processing before deployment in credential stuffing attacks. Golf and sports enthusiast platforms attract users across wide age and professional demographics who frequently reuse thier forum or community passwords on personal email accounts, financial platforms, and retail sites. Once these plaintext credentials enter criminal distribution channels, they remain exploitable indefinitely against any service where the same password was reused.
What Was Exposed
- Email Address
- Password (Plaintext)
Why This Matters
Sports platform users often register with primary personal email addresses used across many other services. A U.S.-based golf news platform breach at nearly 59,000 records is particulary significant because of the extended lifespan of plaintext breach data in criminal combolists. Unlike hashed credential sets that degrade in usefulness as users change passwords, plaintext breaches remain in circulation for years. Victims who have not changed thier ClickitGolf password on other platforms since 2018 remain at active risk of account takeover, identity theft, and financial fraud. Many of these users will have never recieved notification that thier data was exposed.
How Plaintext Password Breaches Work
A plaintext password breach occurs when a platform stores user passwords in their original, readable form rather than converting them to an irreversible hash before storage. When an attacker accesses the database, every password is immediately readable as-is. These login pairs are packaged into combolists and distributed on criminal forums and Telegram channels, where automated tools immediately begin testing each email and password pair against major email services, banking apps, streaming platforms, and e-commerce sites. No cracking step is needed, making plaintext breaches the fastest breach type to exploit at scale.
Check If You Are Affected
HEROIC offers a free identity scanner that searches over 400 billion records, including data from breaches like ClickitGolf. Visit heroic.com to scan your email address and find out if your information was exposed.
Breach Breakdown
58,951 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds