DigitalTown
We noticed a recent surge in credential stuffing attempts targeting accounts associated with a legacy domain, prompting an investigation into its origin. Our analysis led us to a data leak originating from August 21, 2018, on a well-established hacking forum. What struck us was the relatively small number of affected users, 4,642, which initially suggested a limited impact. However, the presence of password hashes, even in an unspecified format, alongside email addresses, presents a persistent risk for account compromise through brute-force or dictionary attacks, especially if these credentials were reused across other services.
The DigitalTown breach, discovered in August 2018, involved a dataset containing 4,642 records. The compromised data primarily consisted of email addresses and associated password hashes. The exact structure of the database from which this data was exfiltrated remains unconfirmed, but the leak originated from a compromised database. This incident falls under the category of a database breach, with the subsequent leak likely contributing to the creation of combolists used in credential stuffing attacks. The significance of this breach lies in the potential for attackers to leverage these hashes, particularly if they are weak or if users have reused their DigitalTown credentials elsewhere. The fact that DigitalTown is now defunct exacerbates the issue, as affected users may not be aware of the breach or have any recourse for password resets.
While specific news coverage directly detailing the DigitalTown breach from 2018 is scarce, the general phenomenon of data leaks from defunct or compromised websites contributing to credential stuffing lists is well-documented. Security researchers have consistently highlighted the ongoing threat posed by such leaks, which often resurface years after the initial compromise. OSINT investigations into similar historical breaches reveal a pattern where data from various sources is aggregated and sold, fueling widespread malicious activity. The format of password hashes, if not properly salted and peppered, can be particularly vulnerable to offline cracking techniques, making even older leaks a relevant concern.
Breach Breakdown
4,642 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds