eMap
We noticed a dataset resurfacing on a well-known cybercrime forum, detailing a breach that occurred on August 21, 2018, affecting eMap, a former Taiwanese national electronic map service. What struck us was the continued availability and potential repurposing of this older data, despite the service's defunct status. The inclusion of plaintext passwords, a critical vulnerability, amplifies the risk of credential stuffing attacks against users who may have reused these credentials across other platforms. The relatively small pwned count of 9,274 records might lead some to underestimate its significance, but the nature of the exposed data demands our attention.
The eMap breach, discovered in August 2018, resulted in the exposure of 9,274 unique records. The leaked data primarily consists of email addresses and plaintext passwords. This type of data, particularly the unencrypted passwords, presents a significant risk for account compromise through credential stuffing. Threat actors frequently leverage such databases to test common password combinations against other services, exploiting user habits of password reuse. The source structure of this leak points to a direct database compromise, where the integrity of stored credentials was fundamentally flawed. The dataset was found posted on a prominent cybercrime forum, indicating its immediate accessibility to malicious actors.
While this specific incident did not garner widespread news coverage at the time of its occurrence, the broader trend of credential data leaks from compromised databases is a persistent concern within cybersecurity discourse. Research from various security firms consistently highlights the ongoing threat posed by credential stuffing, where databases like the one from eMap serve as valuable fuel for these attacks. The fact that this data is still circulating underscores the long-tail risk associated with data breaches, even from services that are no longer operational.
Breach Breakdown
9,274 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds