Deli-Net
We've been tracking an uptick in older breaches resurfacing in combolists and credential stuffing attacks. The age of a breach doesn't diminish its value to attackers, especially when credentials remain valid across multiple services. What caught our attention with this particular dataset wasn't its size, but rather the specific target: Deli-Net, a now-defunct Japanese directory for adult entertainment establishments. The data, dating back to August 2018, provides a snapshot into a specific online community and highlights the long tail of risk associated with seemingly forgotten breaches. The combination of email addresses and varied password hashes makes this breach a valuable resource for attackers targeting individuals who may have reused credentials across other platforms.
Deli-Net Breach: 7,012 Records Resurfaced
The Deli-Net breach, impacting 7,012 users, involved the compromise of both email addresses and password hashes. Discovered on a prominent hacking forum on August 26, 2018, the data originated from a database of a Japanese directory and ranking site for adult entertainment, escort, and nightlife establishments. The passwords were stored using both phpass and MD5 algorithms, both of which are considered weak by modern standards. This breach matters to enterprises because it underscores the persistent risk of older breaches being leveraged in modern attacks. Even though the site is defunct, the exposed credentials can be used to target individuals who may have reused them on other, more sensitive platforms. This incident highlights the importance of continuous monitoring for leaked credentials and proactively addressing password reuse.
- Total records exposed: 7,012
- Types of data included: Email Address, Password Hash
- Sensitive content types: Potentially sensitive browsing history related to adult entertainment
- Source structure: Database
- Leak location(s): Prominent hacking forum
- Dates of first appearance: August 26, 2018
External Context & Supporting Evidence
While Deli-Net itself is not a widely known entity, the incident aligns with broader trends in the cybercrime ecosystem. Combolists, like the one containing this data, are frequently traded and used in automated attacks. The presence of both phpass and MD5 hashes suggests a legacy system that may have been vulnerable to other attacks. Security researcher Troy Hunt's Have I Been Pwned? service has documented this breach since 2018, showing its continued relevance in the threat landscape. Such breaches are often aggregated into larger databases of stolen credentials and used in credential stuffing attacks against a variety of online services.
Breach Breakdown
7,012 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds