Breach Intelligence Report 26 Aug 2025

Data Image Breach Exposes 81,782 Taiwanese Tech Company User Credentials

HEROIC
HEROIC Threat Intelligence Team
Email Address Password Hash
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 81,782
Source Type Database,Combolist
Origin Telegram
Password Type MD5,MD5(PHPBB3)

In August 2018, Data Image, a Taiwanese manufacturer of LCD modules operating at dataimage.com.tw, suffered a data breach that exposed 81,782 user records. The breach involved a database dump containing email addresses and password hashes stored using a mix of MD5 and MD5(PHPBB3) formats, which were subsequently compiled into combolists and distributed across underground criminal forums. Data Image's online platform likely hosted a community forum or user portal supporting its business operations and customer base, with users whose credentials represent a cross-section of technology industry professionals across Taiwan and the broader Asia-Pacific region.

Why This Is Dangerous

Both MD5 and MD5(PHPBB3) password hashing formats provide inadequate protection by modern security standards. MD5 hashes are crackable at billions of operations per second using GPU hardware, while MD5(PHPBB3) adds only a minor iteration that still falls quickly against specialized cracking tools and precomputed rainbow tables. The 81,782 affected accounts represent a significant pool of credentials from a technology manufacturer's user base, where individuals often maintain accounts across multiple professional platforms, technical forums, supplier portals, and business services. Users who reused thier Data Image password elsewhere face ongoing risk from credential stuffing attacks targeting the full range of platforms they use. Technology sector credentials are particularly valued in criminal markets because their owners tend to have access to enterprise systems, development environments, and internal company resources. The continued circulation of this combolist data in criminal markets since 2018 means the threat has not diminished with time.

What Was Exposed

  • Email addresses for 81,782 Data Image registered users
  • Password hashes using MD5 and MD5(PHPBB3) formats (both vulnerable to rapid cracking)
  • Account data from the Taiwanese LCD module manufacturer's online platform
  • Credentials compiled into combolists and distributed across underground forums and Telegram channels

Why This Matters

Manufacturer and technology company user databases are targeted because they often contain the email addresses of business professionals, engineers, and procurement specialists who have access to corporate systems and supplier networks. The 81,782 records exposed in the Data Image breach represent a substantial pool of technology sector credentials. Many affected users almost certainly never recieved any formal breach notification. The use of MD5 and PHPBB3-based hashing -- formats that were already known to be weak by 2018 -- means that a large fraction of these passwords have been recovered and are in active use in credential stuffing operations. The data has been confirmed circulating in combolists targeted at business and technology sector accounts, where a successful login can provide access to far more than just the original platform. The particulary long time this data has been in circulation makes it a persistent threat.

How Database and Combolist Breaches Work

A database breach typically occured when an attacker discovered and exploited a vulnerability in the target platform -- an SQL injection flaw in the forum or portal software, a misconfigured server, or administrative credentials obtained through phishing. Forum platforms running phpBB software have historically been targeted due to well-documented vulnerabilities in older versions. Once the attacker exported the database, cracking tools processed the MD5 and MD5(PHPBB3) hashes to recover plaintext passwords for a substantial portion of the 81,782 accounts. The recovered email-password pairs were formatted into combolists and distributed through criminal markets, where automated tools test them against business portals, supplier networks, and consumer platforms simultaneously. The Data Image combolist has followed this distribution pattern since 2018.

Check If You Are Affected

If you ever registered an account on dataimage.com.tw or any associated Data Image platform to access product information, technical support, or community resources, your email address and password hash were exposed in this breach. Take these steps immediately:

  • Search your email address in HEROIC's breach database to confirm whether your Data Image credentials appear in known breach datasets
  • Change the password you used for Data Image on every platform where you used the same or similar password
  • Prioritize corporate accounts, supplier portals, professional forums, email, and any platforms linked to your business activities
  • Enable two-factor authentication on all important accounts, especially work email and business applications
  • Notify your IT security team if you used your Data Image password on any corporate systems
  • Use a password manager to maintain unique passwords for every account you access

HEROIC's breach monitoring service alerts you in real time when your email address appears in newly discovered breach datasets and combolists. For technology sector professionals affected by the Data Image breach, continuous credential monitoring is an essential component of protecting both personal accounts and the business systems accessible through professional email addresses.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Password Hash
Password Types MD5,MD5(PHPBB3)
Date Leaked 26 Aug 2025
Check in 5 seconds

81,782 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,727 scanned today
Breach Rank #N/A by affected users
Impact Score
3
sensitivity + scale + recency
Est. Financial Impact $591.8K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance