Cowalk Security Breach Exposes User Passwords and Phone Numbers
HEROIC's DarkHive intelligence system discovered the Cowalk data breach, exposing 9,704 records. The breach occured in December 2022 and targeted Cowalk, a Korean advocacy and research platform for disability rights. Compromised data included email addresses, phone numbers, usernames, names, IP addresses, and both hashed and plaintext passwords, putting users at serious risk of account takeover.
Why This Is Dangerous
The presence of plaintext passwords in this breach is the most alarming aspect of the Cowalk incident. Unlike hashed passwords which require cracking, plaintext passwords give attackers immediate, direct access to any account where the victim used the same password. Attackers also gain phone numbers and email addresses, enabling targeted phishing and smishing campaigns. IP addresses reveal approximate geographic locations, which can be combined with names to enable more convincing fraud.
What Was Exposed
- Email Address
- Phone Number
- Password Hash
- Plaintext Password
- First Name
- Username
- IP Address
Why This Matters
Plaintext password leaks are particularly dangerous because they require zero effort from attackers to weaponize. Cybercriminals immediately begin testing exposed credentials against banking sites, email providers, and social media platforms in a process called credential stuffing. When organizations serving vulnerable communities store passwords in plaintext, they demonstrate a fundamental failure to protect thier users. Anyone affected by the Cowalk breach should treat every account where they used the same password as fully compromised and change credentials immediately.
How Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a site's backend data storage, often through SQL injection or poorly secured admin interfaces. The Cowalk breach exposed the particularly serious problem of storing passwords in plaintext or with weak hashing, which means no additional cracking effort is needed once the database is stolen. Breached data is then packaged into structured files and traded on cybercrime forums where it fuels large-scale automated attacks. Smaller advocacy platforms are frequently targeted because they prioritize mission over security infrastructure investment.
Check If You Are Affected
HEROIC offers a free identity scanner that searches over 400 billion records, including data from breaches like Cowalk. Visit heroic.com to scan your email address and find out if your information was exposed.
Breach Breakdown
9,704 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds