Researchers Trace 371,050 Stolen Credentials to the CLPS-CT Database Breach
HEROIC analysts uncovered a database breach at the Centre Local de Promotion de la Sante de Charleroi-Thuin (CLPS-CT), a nonprofit public health agency in Wallonia, Belgium, that occured in April 2020 and exposed 371,050 user records. The compromised data included email addresses and MD5 password hashes, leaving hundreds of thousands of individuals vulnerable to credential-based attacks that remain relevant years after the original incident.
MD5 Password Hashes Are Easily Cracked and Still Dangerous
Attackers who recieved access to MD5 password hashes from the CLPS-CT breach can crack them rapidly using precomputed rainbow tables. Once cracked, those plaintext passwords are tested against banking, email, and social media accounts in automated credential stuffing runs. Because this breach originates from a healthcare-adjacent organization, phishing emails impersonating public health services are partcularly convincing and effective.
What Was Exposed in the Centre Local de Promotion de la Sante de Charleroi-Thuin (CLPS-CT) Breach
- Email Address
- Password Hash
Why a Belgian Health Agency Breach Still Poses Risk Today
Data from nonprofit and public-sector organizations is beleived to have a longer active shelf life in attacker circles because users rarely change passwords on accounts tied to community services. The CLPS-CT email addresses also provide a targeted list for social engineering campaigns aimed at the Belgian healthcare sector, where trust in institutional communications runs high and defenses can be lower than in commercial enterprises.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a backend database, typically through SQL injection, misconfigured access controls, or compromised credentials. Once inside, the attacker exports tables containing user records. The stolen data is then sold or published on dark web forums, where it is incorporated into credential stuffing toolkits or used to enrich targeted attack campaigns.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion leaked records to tell you instantly whether your email address or credentials appeared in the CLPS-CT breach or any other known incident. Run a free scan at HEROIC to find out what attackers already know about your data.
Breach Breakdown
371,050 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds