The Cracked.io Database Breach Contains 515,781 Email and Password Hash Records
HEROIC analysts documented the Cracked.io breach, a database incident that occured in July 2019 when the hacking forum suffered an attack carried out by a rival group. The breach exposed 515,781 records containing email addresses, password hashes, usernames, birthdays, and salts. Passwords were stored using bcrypt, a strong hashing algorithm, but the combination of usernames, emails, and birthdays creates meaningful risk for affected users across other platforms where they may have recieved accounts with the same credentials.
How Bcrypt Password Hashes, Usernames, and Birthdays from a Hacking Forum Create Cross-Platform Risk
The Cracked.io breach is partcularly notable because the affected users are members of a hacking community. Usernames from this forum may match handles used across other criminal and legitimate platforms, making it possible for rival threat actors or law enforcement to map identities. Even though bcrypt hashes are computationally expensive to crack, the birthday and salt data included in this breach assist in narrowing candidate passwords, and the passage of time plus advancing GPU capability means older bcrypt hashes become increasingly accessable to cracking attempts.
What Was Exposed in the Cracked.io Breach
- Email Address
- Password Hash
- Username
- Birthday
- Salt
Why Cracked.io Forum Credentials Pose a Unique Threat to Platform Security
Members of hacking forums often reuse usernames and email addresses across multiple platforms, including legitimate services. A credential set from Cracked.io that is successfully cracked can be used to access banking apps, cloud services, or corporate email systems where the same user registered with the same email address. The breach data is beleived to have circulated on competing forums and dark web marketplaces since 2019, giving threat actors years to attempt cracking and cross-platform exploitation.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a backend data store, typically through exploiting a vulnerability, using stolen credentials, or leveraging a misconfigured server. In the case of Cracked.io, the attack was attributed to a rival hacking group that targeted the forum's infrastructure directly. The stolen database was then shared on competing forums as a demonstration of capability and to damage the reputation of the breached platform.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion records to determine whether your email address appears in the Cracked.io breach or any other known incident. Run a free scan now to see what credentials and personal information may be in circulation about you.
Breach Breakdown
515,781 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds