Eroticy
We've seen a resurgence of older breaches surfacing in aggregated credential dumps lately, often repackaged and sold as new. While the volume is lower than current stealer log datasets, the fact that plaintext passwords persist in these older breaches remains a significant concern. Our team flagged a recent re-emergence of the Eroticy breach from 2015. What really struck us wasn't the size – around 1.6 million records – but the continued presence of plaintext passwords nearly a decade later, highlighting the long tail of risk associated with poor security practices and the enduring value of seemingly "old" data to threat actors.
Eroticy's 2015 Leak: Plaintext Passwords Haunt Users a Decade Later
The alleged breach of the adult website Eroticy, dating back to June 1, 2015, continues to pose a risk to individuals even in 2024. The data, which includes approximately 1,593,369 unique accounts, resurfaced recently on multiple underground forums. While the exact method of the breach remains unconfirmed, the impact is clear: exposed email addresses and, critically, plaintext passwords. The presence of plaintext passwords is what distinguishes this breach, underscoring a severe lack of basic security measures at the time.
The breach initially caught widespread attention in mid-2016 when large portions of the data began circulating online. The data’s reappearance now, years later, underscores the persistent nature of compromised credentials. This is not simply a case of outdated information; the re-emergence of the Eroticy data highlights how older breaches can be repackaged and exploited in credential stuffing attacks, account takeovers, and other malicious activities. Enterprises should be aware of this trend, as employees may have reused these passwords on corporate accounts.
The Eroticy breach matters to enterprises today because it exemplifies the enduring risk of poor password management and the long-term consequences of inadequate security practices. It's a potent reminder that even breaches from almost a decade ago can still provide valuable attack vectors for threat actors. This ties into broader threat themes surrounding credential reuse and the automation of attacks using readily available breach data.
- Total records exposed: 1,593,369
- Types of data included: Email Address, Plaintext Password
- Sensitive content types: None beyond PII
- Source structure: Unknown (likely a database dump)
- Leak location(s): Various underground forums and credential stuffing lists.
- Date of first appearance: Allegedly June 1, 2015, with wider circulation in 2016.
While the Eroticy breach itself didn't generate extensive mainstream media coverage, its inclusion in larger compilations of leaked credentials has been noted in security circles. For example, discussions on Reddit's r/security and r/privacy often highlight the risks associated with older breaches resurfacing. The breach has also been included in various threat intelligence feeds and is often cited as an example of the dangers of storing passwords in plaintext.
Breach Breakdown
1,593,369 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds