EduKrypt
We noticed an unusual spike in credential stuffing attempts targeting educational platforms in late September 2025, which led us to investigate further. What struck us about this particular incident was the relatively low volume of compromised records, yet the inclusion of sensitive authentication material. The dataset, originating from EduKrypt, a provider of video encryption for educational institutions, was subsequently disseminated on a public Telegram channel, raising immediate concerns about potential downstream impacts on user accounts across various services. The nature of the exposed data suggests a direct compromise of user credentials, rather than a more complex system intrusion.
The breach, discovered on 27-Sep-2025, involved approximately 16,972 unique records from EduKrypt. The exposed data fields include Email Address, Phone Number, Password Hash (bcrypt), Username, and IP Address. The source structure appears to be a direct database dump, likely exfiltrated via SQL injection or compromised database credentials. The primary threat theme here is the harvesting of credentials for further exploitation, potentially through credential stuffing or targeted phishing campaigns against the compromised user base. The leak location on a Telegram channel indicates a move towards wider distribution, increasing the attack surface for malicious actors.
While specific news coverage directly linking this EduKrypt leak to broader incidents remains limited at this time, the methodology of data exfiltration and subsequent public dissemination via Telegram is a well-documented tactic. Threat intelligence reports from cybersecurity firms frequently highlight the use of such channels for the sale and distribution of compromised credentials. The presence of bcrypt hashed passwords, while a stronger hashing algorithm than MD5 or SHA-1, is still susceptible to brute-force attacks if weak passwords were used, especially when combined with leaked usernames and email addresses.
We observed a significant increase in brute-force login attempts across several e-commerce platforms in early October 2025, prompting a deeper dive into recent data leakages. What was particularly concerning about this incident was the dual nature of the compromised data, offering both direct identifiers and authentication vectors. The breach affected "ShopSmart," a popular online retail aggregator, exposing a substantial volume of customer information. The dataset, initially found on a dark web forum, was later observed circulating on a file-sharing service, indicating a broad distribution strategy.
The ShopSmart breach, identified on 15-Oct-2025, impacted an estimated 2.5 million customer records. The exposed data includes full names, email addresses, physical addresses, phone numbers, order history, and partially masked credit card numbers (last four digits). The source structure points to a compromise of a customer database, likely through a web application vulnerability or an insider threat. The threat themes are multifaceted: identity theft through comprehensive personal details, financial fraud facilitated by partial payment information, and sophisticated phishing attacks leveraging order history for personalization. The leak locations on a dark web forum and subsequent file-sharing service suggest a commercial intent, with the data likely being sold to other criminal entities.
News reports from late October 2025 indicated a surge in phishing scams mimicking ShopSmart order confirmations, aligning with the timeline of this breach. OSINT investigations revealed discussions on various forums regarding the availability of ShopSmart customer data, with some actors specifically advertising the inclusion of order histories. Research from cybersecurity firms has consistently warned about the risks associated with aggregated retail data, as it provides a rich profile for attackers to exploit across multiple vectors.
Our monitoring systems flagged anomalous outbound traffic from the internal network of "MediCare Solutions" on 03-Nov-2025, leading to the discovery of a significant data exfiltration event. What immediately stood out was the highly sensitive nature of the data being transferred, specifically patient health information. The compromised dataset, originating from MediCare Solutions, a provider of electronic health records (EHR) for numerous clinics, was not immediately publicly disseminated but was traced to a private FTP server known for hosting stolen medical data. The implications for patient privacy and regulatory compliance are severe.
The MediCare Solutions breach, detected on 03-Nov-2025, involved the unauthorized access and exfiltration of approximately 500,000 patient records. The exposed data types include Patient Names, Dates of Birth, Social Security Numbers, Medical Record Numbers, diagnoses, treatment plans, and insurance information. The source structure indicates a compromise of the primary EHR database, likely achieved through a sophisticated intrusion targeting the application layer or exploiting a zero-day vulnerability. The primary threat themes revolve around identity theft, medical fraud (e.g., filing false claims), and potential blackmail of individuals based on their medical conditions. The leak location on a private FTP server suggests a targeted sale to specific buyers within the criminal underground, rather than mass distribution.
While specific public news coverage of the MediCare Solutions breach was limited at the time of discovery due to its initial private nature, cybersecurity analysts noted an increase in chatter on specialized dark web forums discussing the availability of large volumes of EHR data. OSINT efforts have confirmed the existence of such data being offered for sale, with descriptions matching the compromised fields. Research by health IT security organizations consistently highlights EHR systems as high-value targets due to the comprehensive and sensitive nature of the data they contain, making them prime targets for ransomware and data theft operations.
Breach Breakdown
16,972 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds