CSW Contractors
We noticed a significant data exposure originating from CSW Contractors, a US-based heavy civil engineering and construction firm. The incident, which came to light on August 26, 2018, involved a breach of their online portal. What struck us was the inclusion of plaintext passwords alongside email addresses, a critical vulnerability that dramatically increases the risk of credential stuffing attacks and further compromise.
The breach, classified as a database compromise, resulted in the exposure of 12,175 records. The leaked data primarily consists of email addresses and, alarmingly, plaintext passwords. This suggests a direct compromise of a database storing user credentials without adequate hashing or salting. The compromised information was subsequently disseminated on a well-known hacking forum, increasing its accessibility to malicious actors. The nature of the data and its distribution points towards a potential combolist creation, where this dataset could be used to attempt unauthorized access across other online services.
While there was no widespread news coverage directly linked to this specific breach at the time of its discovery, the presence of plaintext credentials in a data leak of this size is a recurring theme in cybersecurity incidents. Such exposures often fuel credential stuffing campaigns, as detailed in research by organizations like Verizon in their annual Data Breach Investigations Report, which consistently highlights the impact of compromised credentials on enterprise security.
Breach Breakdown
12,175 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds