EvilLabs Security Breach Exposes 47K User Credentials
HEROIC's DarkHive intelligence system discovered the EvilLabs data breach, exposing 46,929 records. The breach occured in November 2017, affecting this Slovakian software provider known for free lyrics search and karaoke display software. Email addresses and plaintext passwords were leaked, creating immediate risks for all affected users.
Why This Is Dangerous
EvilLabs stored user passwords in plaintext, meaning that every single password exposed in this breach is ready-to-use with no additional work required by attackers. Cybercriminals can take these email and password pairs and immediately begin testing them against high-value services like email providers, banks, and e-commerce sites. Software communities often attract users who are technically inclined but may still reuse passwords across development tools, code repositories, and professional accounts, amplifying the downstream risk of this breach.
What Was Exposed
- Email Address
- Plaintext Password
Why This Matters
The EvilLabs breach contributes directly to the pool of credentials used in credential stuffing campaigns that target software developers and technical users. Developers often have access to code repositories, cloud infrastructure, and internal company systems. If thier EvilLabs credentials were reused anywhere in a professional context, attackers could gain access to corporate networks, source code, or cloud environments. This breach highlights how a breach at a small niche software tool can have far-reaching consequences in the enterprise security landscape.
How Database Breach Works
A database breach occurs when attackers access a web application's backend database through vulnerabilities such as SQL injection, insecure authentication, or unpatched server software. The fact that EvilLabs stored passwords as plaintext, rather than using modern hashing algorithms like bcrypt or Argon2, represents a critical security failure that made this breach far more damaging than it needed to be. Once the database was accessed, every user's password was immediately readable, leaving no cryptographic protection for affected accounts.
Check If You Are Affected
HEROIC offers a free identity scanner that searches over 400 billion records, including data from breaches like EvilLabs. Visit heroic.com to scan your email address and find out if your information was exposed.
Breach Breakdown
46,929 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds