199,555 Plaintext Passwords From the Egrulpiter Database Just Surfaced on the Dark Web
HEROIC analysts found the Egrulpiter breach dataset containing 199,555 records from the Russian business registration information platform. The data, which occured in April 2021, includes email addresses alongside plaintext passwords, meaning the actual passwords were stored with no encryption or hashing whatsoever. The dataset has been observed circulating on threat actor forums and represents an immediate credential risk for affected users.
Plaintext Passwords Give Attackers Instant Access to Every Account
Unlike hashed passwords, plaintext credentials require no cracking. An attacker who obtains this Egrulpiter dataset can immediately attempt to log into each user's email account, banking portal, and any other service where the same password was reused. This makes plaintext password breaches partcularly dangerous, as the time between data acquisition and successful account takeover can be measured in minutes rather than days.
What Was Exposed in the Egrulpiter Breach
- Email Address
- Plaintext Password
Why Ready-to-Use Credentials Fuel Large-Scale Credential Stuffing
The 199,555 email and plaintext password pairs from Egrulpiter are immediately accessable for use in automated credential stuffing attacks. Tools like Sentry MBA and OpenBullet allow threat actors to test these credentials across hundreds of popular websites simultaneously. Even a low success rate across a large list translates to thousands of compromised accounts, enabling identity theft, financial fraud, and unauthorized access to corporate systems if any affected users also held work accounts with the same password. This type of data has recieved consistent demand on dark web markets because it requires no technical skill to exploit.
How Database Breaches Work
A database breach occurs when an unauthorized party gains access to the backend storage of a platform and extracts user records. When that platform stores passwords in plaintext rather than using a secure hashing algorithm, the damage is maximized. Every credential in the database is immediately usable with no additional processing required, making plaintext storage one of the most consequential security failures a platform can commit.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records, including the Egrulpiter dataset. Enter your email address to find out instantly whether your credentials were exposed in this or any other known breach, and get guidance on securing your accounts right away.
Breach Breakdown
199,555 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds