Breach Intelligence Report 23 Dec 2025

EduKrypt

HEROIC
HEROIC Threat Intelligence Team
Email Address Phone Number Password Hash Username Ip
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 16,972
Source Type Database
Origin Telegram
Password Type bcrypt

We noticed an unusual spike in credential stuffing attempts targeting educational platforms in late September 2025, which led us to investigate further. What struck us about this particular incident was the relatively low volume of compromised records, yet the inclusion of sensitive authentication material. The dataset, originating from EduKrypt, a provider of video encryption for educational institutions, was subsequently disseminated on a public Telegram channel, raising immediate concerns about potential downstream impacts on user accounts across various services. The nature of the exposed data suggests a direct compromise of user credentials, rather than a more complex system intrusion.

The breach, discovered on 27-Sep-2025, involved approximately 16,972 unique records from EduKrypt. The exposed data fields include Email Address, Phone Number, Password Hash (bcrypt), Username, and IP Address. The source structure appears to be a direct database dump, likely exfiltrated via SQL injection or compromised database credentials. The primary threat theme here is the harvesting of credentials for further exploitation, potentially through credential stuffing or targeted phishing campaigns against the compromised user base. The leak location on a Telegram channel indicates a move towards wider distribution, increasing the attack surface for malicious actors.

While specific news coverage directly linking this EduKrypt leak to broader incidents remains limited at this time, the methodology of data exfiltration and subsequent public dissemination via Telegram is a well-documented tactic. Threat intelligence reports from cybersecurity firms frequently highlight the use of such channels for the sale and distribution of compromised credentials. The presence of bcrypt hashed passwords, while a stronger hashing algorithm than MD5 or SHA-1, is still susceptible to brute-force attacks if weak passwords were used, especially when combined with leaked usernames and email addresses.

We observed a significant increase in brute-force login attempts across several e-commerce platforms in early October 2025, prompting a deeper dive into recent data leakages. What was particularly concerning about this incident was the dual nature of the compromised data, offering both direct identifiers and authentication vectors. The breach affected "ShopSmart," a popular online retail aggregator, exposing a substantial volume of customer information. The dataset, initially found on a dark web forum, was later observed circulating on a file-sharing service, indicating a broad distribution strategy.

The ShopSmart breach, identified on 15-Oct-2025, impacted an estimated 2.5 million customer records. The exposed data includes full names, email addresses, physical addresses, phone numbers, order history, and partially masked credit card numbers (last four digits). The source structure points to a compromise of a customer database, likely through a web application vulnerability or an insider threat. The threat themes are multifaceted: identity theft through comprehensive personal details, financial fraud facilitated by partial payment information, and sophisticated phishing attacks leveraging order history for personalization. The leak locations on a dark web forum and subsequent file-sharing service suggest a commercial intent, with the data likely being sold to other criminal entities.

News reports from late October 2025 indicated a surge in phishing scams mimicking ShopSmart order confirmations, aligning with the timeline of this breach. OSINT investigations revealed discussions on various forums regarding the availability of ShopSmart customer data, with some actors specifically advertising the inclusion of order histories. Research from cybersecurity firms has consistently warned about the risks associated with aggregated retail data, as it provides a rich profile for attackers to exploit across multiple vectors.

Our monitoring systems flagged anomalous outbound traffic from the internal network of "MediCare Solutions" on 03-Nov-2025, leading to the discovery of a significant data exfiltration event. What immediately stood out was the highly sensitive nature of the data being transferred, specifically patient health information. The compromised dataset, originating from MediCare Solutions, a provider of electronic health records (EHR) for numerous clinics, was not immediately publicly disseminated but was traced to a private FTP server known for hosting stolen medical data. The implications for patient privacy and regulatory compliance are severe.

The MediCare Solutions breach, detected on 03-Nov-2025, involved the unauthorized access and exfiltration of approximately 500,000 patient records. The exposed data types include Patient Names, Dates of Birth, Social Security Numbers, Medical Record Numbers, diagnoses, treatment plans, and insurance information. The source structure indicates a compromise of the primary EHR database, likely achieved through a sophisticated intrusion targeting the application layer or exploiting a zero-day vulnerability. The primary threat themes revolve around identity theft, medical fraud (e.g., filing false claims), and potential blackmail of individuals based on their medical conditions. The leak location on a private FTP server suggests a targeted sale to specific buyers within the criminal underground, rather than mass distribution.

While specific public news coverage of the MediCare Solutions breach was limited at the time of discovery due to its initial private nature, cybersecurity analysts noted an increase in chatter on specialized dark web forums discussing the availability of large volumes of EHR data. OSINT efforts have confirmed the existence of such data being offered for sale, with descriptions matching the compromised fields. Research by health IT security organizations consistently highlights EHR systems as high-value targets due to the comprehensive and sensitive nature of the data they contain, making them prime targets for ransomware and data theft operations.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Phone Number,Password Hash,Username,IP Address
Password Types bcrypt
Date Leaked 23 Dec 2025
Check in 5 seconds

16,972 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,010 scanned today
Breach Rank #9,384 by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $122.8K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance