Breach Intelligence Report 26 Aug 2025

119,978 Cosensa Users Exposed in UK Training Platform Breach

HEROIC
HEROIC Threat Intelligence Team
Email Address Plaintext Password
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 119,978
Source Type Database,Combolist
Origin Telegram
Password Type Plaintext

In August 2018, Cosensa, a UK-based professional training and organizational development provider, suffered a data breach that exposed the account credentials of 119,978 users. The breach involved a database dump containing email addresses and plaintext passwords, which were subsequently compiled into combolists and circulated across underground forums and dark web markets. Cosensa specializes in leadership development, management training, and professional qualifications for businesses and public sector organizations across the UK -- a user base of professionals whose corporate email addresses and reused passwords represent attractive targets for business email compromise and corporate account takeover attacks.

Why This Is Dangerous

Plaintext password storage represents a complete failure of credential security. When a database containing plaintext passwords is exfiltrated, every single user's actual password is immediately available to the attacker -- no cracking, no computation, no delay. For Cosensa's 119,978 affected users, thier passwords were exposed without any protective barrier. Professional training platform users frequently use the same password across corporate systems, VPNs, Microsoft 365 accounts, and other business tools, making the cascading risk from a single plaintext breach extremely serious. Attackers who obtain corporate email addresses paired with actual passwords can attempt direct access to organization email systems, cloud platforms, and internal applications. Credential stuffing attacks using this data target UK corporate and government platforms where Cosensa clients work, potentially enabling unauthorized access to sensitive business systems and confidential information. The continued circulation of this dataset in underground markets means the threat has not diminished since 2018.

What Was Exposed

  • Email addresses for 119,978 Cosensa registered users
  • Plaintext passwords stored without any hashing or encryption
  • Account data associated with Cosensa's UK professional training platform
  • Credentials compiled into combolists circulated on dark web forums and Telegram channels

Why This Matters

Professional training platforms serving business and public sector clients represent a uniquely valuable target for attackers because their user databases consist largely of professionals with access to corporate systems. Nearly 120,000 plaintext passwords from a UK professional development provider gives attackers direct credentials to test against Microsoft 365, Google Workspace, corporate VPNs, and government portals. Many affected users almost certainly never recieved any breach notification from Cosensa. The scale of this breach -- nearly 120,000 records -- combined with plaintext password storage makes it particulary significant among UK professional services data exposures. Organizations whose employees trained through Cosensa face ongoing risk if those employees reused their Cosensa passwords in corporate environments.

How Database and Combolist Breaches Work

A database breach typically occured when an attacker identified and exploited a vulnerability in the target web application -- such as an SQL injection flaw, a misconfigured server, or compromised administrative credentials. Once inside, the attacker exported the user account table. When that table stores passwords in plaintext rather than using a hashing algorithm, the breach immediately delivers complete, ready-to-use credentials. The stolen data gets organized into combolists and distributed through underground markets, where automated credential stuffing tools test every email-password pair against target websites. Professional and corporate platforms are prioritized targets because successful logins can yield access to business systems with financial and data value. The Cosensa combolist has circulated in these markets since 2018 and continues to appear in active datasets.

Check If You Are Affected

If you ever registered an account on cosensa.co.uk to access professional training courses, management qualifications, or organizational development resources, your email address and actual password were exposed in this breach. Take these steps immediately:

  • Search your email address in HEROIC's breach database to confirm whether your Cosensa credentials appear in known breach datasets
  • Change the password you used for Cosensa on every platform where you used the same or similar password
  • Prioritize your work email account, corporate VPN, Microsoft 365 or Google Workspace, and any government or public sector portals
  • Notify your IT security team if you used your Cosensa password in corporate systems
  • Enable multi-factor authentication on all work and personal accounts immediately
  • Use a password manager to generate and store unique passwords for each account going forward

HEROIC's breach monitoring service provides real-time alerts when your credentials appear in newly discovered breach datasets and combolists. For professionals whose email addresses and plaintext passwords were exposed in the Cosensa breach, continuous monitoring and immediate password hygiene are essential steps to reduce ongoing risk to personal and organizational accounts.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Plaintext Password
Password Types Plaintext
Date Leaked 26 Aug 2025
Check in 5 seconds

119,978 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,451 scanned today
Breach Rank #3,746 by affected users
Impact Score
5
sensitivity + scale + recency
Est. Financial Impact $868.2K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance