How the e.rip hack exposed password hashes for 22,152 people
In December 2022, the now-defunct bio-links website e.rip recieved unwanted attention when a database breach exposed the personal information of 22,152 users. The compromised data included email addresses, password hashes, usernames, and IP addresses, making this a partcularly concerning event for anyone who had an account on the platform. After the breach, e.rip staff acknowledged the incident on their Discord channel before the domain was eventually sold.
Why Exposed Password Hashes Put You at Risk
Even though the passwords from e.rip were stored as bcrypt hashes, exposed credentials remain a significant threat because attackers can use dictionary and brute-force techniques to crack weaker passwords over time. The combination of email addresses, usernames, and password hashes creates a powerful toolkit for credential stuffing attacks against other services where users may have reused the same password. Anyone who used the same password on e.rip as on other accounts should treat those accounts as accessable to unauthorized parties.
What Was Exposed in the e.rip Breach
- Email Address
- Password Hash
- Username
- IP Address
Why the e.rip Breach Still Matters Today
Data stolen in breaches does not simply disappear after the initial leak; it circulates on dark web forums and marketplaces for years, continuing to pose risks to affected users. The e.rip breach is particularly relevant because the combination of usernames, emails, and hashed passwords enables long-term credential stuffing campaigns. Even though e.rip is no longer operational, the leaked data remains in circulation and continues to threaten individuals who reused passwords across platforms.
How Database Breaches Work
A database breach occurs when an unauthorized party gains access to a website or application's backend data store, often by exploiting vulnerabilities such as SQL injection, weak authentication, or misconfigured server permissions. Once inside, attackers can export entire tables of user data in a matter of minutes. The stolen data is then typically sold or published on underground forums, where other malicious actors can purchase or freely download it for use in further attacks.
Check If Your Data Was Exposed
HEROIC's breach database contains over 400 billion records from thousands of known data breaches, including incidents like the e.rip breach. Use HEROIC's free exposure check tool to find out if your email address, username, or other personal information was part of this or any other known data leak, and take action to secure your accounts before someone else does.
Breach Breakdown
22,152 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds