EyeQuest Manpower Services Data Breach Report
Our monitoring systems flagged a significant exposure originating from EyeQuest International Manpower Services, a Philippines-based entity facilitating overseas employment for Filipino workers. The incident, dating back to August 26, 2018, involved a substantial dataset of approximately 12,000 records. What immediately stood out was the inclusion of plaintext passwords alongside email addresses, a critical vulnerability that significantly amplifies the risk of credential stuffing and unauthorized account access. The discovery of this data on a public hacking forum underscores the immediate and widespread threat posed by such exposures.
The breach at EyeQuest International Manpower Services appears to have originated from a database compromise, resulting in the exfiltration of 11,987 unique records. The exposed data primarily consists of email addresses and, critically, plaintext passwords. This combination is a classic indicator of a potential combolist formation, where compromised credentials are aggregated for subsequent misuse across various online platforms. The fact that this data was shared on a popular hacking forum means it's likely already being actively exploited by malicious actors, posing a direct threat to the individuals whose information was compromised and potentially to the integrity of the EyeQuest International Manpower Services platform itself.
External Context and Research
While specific news coverage directly detailing this particular EyeQuest International Manpower Services breach from 2018 is limited, the broader context of data breaches affecting recruitment agencies and the subsequent availability of credentials on dark web forums is well-documented. Research from cybersecurity firms consistently highlights the prevalence of credential stuffing attacks, often fueled by combolists derived from such database leaks. The practice of storing sensitive user information, particularly passwords, in plaintext is a foundational security failing that has been repeatedly warned against by security professionals and regulatory bodies globally. The discovery of this data on a public forum suggests it may have been part of a larger, more widespread credential stuffing campaign or intended for resale to actors specializing in account takeover.
Breach Breakdown
11,987 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds