Data Image Breach Exposes 81,782 Taiwanese Tech Company User Credentials
In August 2018, Data Image, a Taiwanese manufacturer of LCD modules operating at dataimage.com.tw, suffered a data breach that exposed 81,782 user records. The breach involved a database dump containing email addresses and password hashes stored using a mix of MD5 and MD5(PHPBB3) formats, which were subsequently compiled into combolists and distributed across underground criminal forums. Data Image's online platform likely hosted a community forum or user portal supporting its business operations and customer base, with users whose credentials represent a cross-section of technology industry professionals across Taiwan and the broader Asia-Pacific region.
Why This Is Dangerous
Both MD5 and MD5(PHPBB3) password hashing formats provide inadequate protection by modern security standards. MD5 hashes are crackable at billions of operations per second using GPU hardware, while MD5(PHPBB3) adds only a minor iteration that still falls quickly against specialized cracking tools and precomputed rainbow tables. The 81,782 affected accounts represent a significant pool of credentials from a technology manufacturer's user base, where individuals often maintain accounts across multiple professional platforms, technical forums, supplier portals, and business services. Users who reused thier Data Image password elsewhere face ongoing risk from credential stuffing attacks targeting the full range of platforms they use. Technology sector credentials are particularly valued in criminal markets because their owners tend to have access to enterprise systems, development environments, and internal company resources. The continued circulation of this combolist data in criminal markets since 2018 means the threat has not diminished with time.
What Was Exposed
- Email addresses for 81,782 Data Image registered users
- Password hashes using MD5 and MD5(PHPBB3) formats (both vulnerable to rapid cracking)
- Account data from the Taiwanese LCD module manufacturer's online platform
- Credentials compiled into combolists and distributed across underground forums and Telegram channels
Why This Matters
Manufacturer and technology company user databases are targeted because they often contain the email addresses of business professionals, engineers, and procurement specialists who have access to corporate systems and supplier networks. The 81,782 records exposed in the Data Image breach represent a substantial pool of technology sector credentials. Many affected users almost certainly never recieved any formal breach notification. The use of MD5 and PHPBB3-based hashing -- formats that were already known to be weak by 2018 -- means that a large fraction of these passwords have been recovered and are in active use in credential stuffing operations. The data has been confirmed circulating in combolists targeted at business and technology sector accounts, where a successful login can provide access to far more than just the original platform. The particulary long time this data has been in circulation makes it a persistent threat.
How Database and Combolist Breaches Work
A database breach typically occured when an attacker discovered and exploited a vulnerability in the target platform -- an SQL injection flaw in the forum or portal software, a misconfigured server, or administrative credentials obtained through phishing. Forum platforms running phpBB software have historically been targeted due to well-documented vulnerabilities in older versions. Once the attacker exported the database, cracking tools processed the MD5 and MD5(PHPBB3) hashes to recover plaintext passwords for a substantial portion of the 81,782 accounts. The recovered email-password pairs were formatted into combolists and distributed through criminal markets, where automated tools test them against business portals, supplier networks, and consumer platforms simultaneously. The Data Image combolist has followed this distribution pattern since 2018.
Check If You Are Affected
If you ever registered an account on dataimage.com.tw or any associated Data Image platform to access product information, technical support, or community resources, your email address and password hash were exposed in this breach. Take these steps immediately:
- Search your email address in HEROIC's breach database to confirm whether your Data Image credentials appear in known breach datasets
- Change the password you used for Data Image on every platform where you used the same or similar password
- Prioritize corporate accounts, supplier portals, professional forums, email, and any platforms linked to your business activities
- Enable two-factor authentication on all important accounts, especially work email and business applications
- Notify your IT security team if you used your Data Image password on any corporate systems
- Use a password manager to maintain unique passwords for every account you access
HEROIC's breach monitoring service alerts you in real time when your email address appears in newly discovered breach datasets and combolists. For technology sector professionals affected by the Data Image breach, continuous credential monitoring is an essential component of protecting both personal accounts and the business systems accessible through professional email addresses.
Breach Breakdown
81,782 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds