The Equity Development Breach: Passwords Sat Unhashed Since 2016
HEROIC analysts identified a resurfaced 2016 database breach tied to Equity Development, a UK-based investment research firm, exposing 4,448 accounts. The breach originally occurred on March 30, 2016, and includes email addresses paired with passwords that were stored in plaintext, meaning no hashing or encryption protected them at all.
Why the Equity Development Breach Is Dangerous
Plaintext password storage is about as bad as it gets for a breach. There's no hash to crack and no encryption to break: the passwords are exposed exactly as users typed them. For anyone in this dataset, an attacker doesn't need any special tools or time to use the stolen password. It works immediately, on this account and potentially on any other account where the same password was used.
What Was Exposed in the Equity Development Breach
- Email addresses
- Passwords (stored in plaintext)
Why This Breach Matters
Because these passwords were never hashed, this breach carries more risk per record than many larger breaches involving properly hashed credentials. Anyone who registered with Equity Development and reused that exact password on another account, like email, banking, or social media, is exposed to immediate credential stuffing and account takeover. The small scale of this breach doesn't reduce the danger to the individuals involved.
How This Database Breach Happened
This incident is classified as a database breach, where an attacker gained direct access to Equity Development's stored records. The use of plaintext passwords suggests the site was not following basic security practices at the time of the breach, which made the data immediately usable the moment it was stolen, rather than requiring the cracking process that hashed passwords typically demand. Since then, the data has circulated on Telegram channels used to trade older breach dumps.
Check If You Are Affected
If you ever had an account with Equity Development, treat this as a priority to check. HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including this breach, and shows you immediately if your password was exposed in plaintext.
Breach Breakdown
4,448 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds