13,633 MD5-Hashed Passwords From the Escaquejant Breach Surfaced
HEROIC analysts identified a dataset tied to Escaquejant, a Catalan community platform for chess enthusiasts, that surfaced on a hacking forum. The breach is dated July 8, 2018, and contains 13,633 records, each pairing a member's email address with their password stored as an MD5 hash. The exposure affected users in Spain and is classified as both a database exposure and a combolist.
Why the Escaquejant Breach Is Dangerous
Unlike a plaintext leak, these passwords were run through MD5 hashing before being exposed, which sounds safer but is not. MD5 is an outdated hashing method that modern computers can crack in bulk within minutes using freely available tools, especially for common or simple passwords. In practice, this means the vast majority of these 13,633 hashed passwords can be reversed back into their original, readable form with very little effort.
What Was Exposed in the Escaquejant Breach
- Email addresses
- MD5-hashed passwords
Why This Matters
Once an MD5 hash is cracked, the result is a plain, working password, and from there the same risks apply as with any other leaked credential. If a chess club member used their Escaquejant password anywhere else, cracking that hash could hand an attacker access to their email, banking, or social media account. Attackers routinely crack batches of weak hashes like these and feed the results into credential stuffing tools that test the recovered passwords against dozens of other sites at once.
How a Database and Combolist Breach With Weak Hashing Happens
This breach is tagged as both a database exposure and a combolist, meaning Escaquejant's stored records were compromised directly and then packaged for distribution on hacking forums. The use of MD5 to store passwords made the situation worse than it needed to be: proper modern hashing methods are designed to be slow and resistant to cracking, while MD5 was built for speed and offers little real protection once a database is stolen. That gap is exactly why attackers target older or smaller platforms that never upgraded their security practices.
Check If You Were Affected by the Escaquejant Leak
If you were ever a member of Escaquejant or reuse the same password across multiple accounts, it is worth checking whether your information appeared in this breach. HEROIC's free breach scanner checks your email address against a database of more than 400 billion leaked records, including this one, so you can find out in seconds whether it is time to change a password.
Breach Breakdown
13,633 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds