How a 2016 Database Breach Exposed 78,999 DAC Group Records
HEROIC analysts identified a resurfaced 2016 database breach tied to DAC Group, a digital marketing agency, exposing 78,999 records. The breach originally occurred on March 31, 2016, and includes first names, last names, email addresses, and passwords protected with the bcrypt hashing algorithm. Though bcrypt is a stronger hashing method than many older breaches use, the data has continued to circulate on underground forums for years.
Why the DAC Group Breach Is Dangerous
Bcrypt is a much harder password hash to crack than older algorithms like MD5 or SHA-1, which is one reason this data has stayed valuable to attackers for so long: cracking it takes real computing time and effort, but it isn't impossible, especially for weak or common passwords. Combined with real first and last names and email addresses, this dataset gives attackers enough personal detail to craft convincing phishing emails or attempt to reset passwords on other accounts belonging to the same people.
What Was Exposed in the DAC Group Breach
- First names
- Last names
- Email addresses
- Passwords (bcrypt hashed)
Why This Breach Matters
A breach at a marketing agency might not sound alarming at first, but agencies like DAC Group hold client contact data and employee credentials that can open doors well beyond the company itself. If any of the 78,999 people in this breach reused their DAC Group password on a work email account or another business tool, attackers could use that overlap to move from a marketing database breach into a full business email compromise, complete with credential stuffing, invoice fraud, or identity theft attempts.
How This Database Breach Happened
This is classified as a database breach, meaning attackers gained direct access to the records DAC Group stored on its servers, typically through a software vulnerability or misconfigured system rather than tricking individual users. Once a database like this is copied out, it doesn't just disappear. It gets traded, bundled with other breaches, and resold on dark web marketplaces for years, which is exactly the pattern that brought this 2016 incident back into circulation.
Check If You Are Affected
If you've ever worked with or been a client of DAC Group, it's worth finding out whether your information appears in this breach. HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records, including this one, and tells you right away if you need to change a password.
Breach Breakdown
78,999 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds