EZ Adboard Ads
We noticed a concerning data exposure originating from EZ Adboard Ads, an online advertising platform based in the United States. The breach, which occurred around July 9, 2018, resulted in the compromise of approximately 14,903 user records. What struck us immediately was the inclusion of plaintext passwords alongside email addresses, a particularly egregious security lapse that significantly amplifies the risk to affected users. The subsequent dissemination of this data on a prominent hacking forum underscores the immediate and widespread threat posed by this incident.
The EZ Adboard Ads breach appears to have stemmed from a direct database compromise. The leaked data, totaling 14,903 records, exclusively contained email addresses and, critically, plaintext passwords. This indicates a fundamental failure in password hashing or encryption mechanisms within their database infrastructure. The source structure suggests a direct dump of user credentials, likely facilitated through SQL injection or compromised administrative access. The leak's primary location was a well-known hacking forum, making the data readily accessible to malicious actors seeking to leverage it for credential stuffing attacks or further exploitation.
While this specific incident from 2018 did not garner widespread media attention at the time, it serves as a stark reminder of the persistent threat posed by insecure data storage practices. The nature of the leaked data, particularly the plaintext passwords, aligns with historical trends of breaches targeting less sophisticated platforms or those with outdated security protocols. The availability of such credential dumps on forums is a well-documented phenomenon, often fueling subsequent attacks against other services where users may have reused credentials. Security researchers have consistently highlighted the dangers of plaintext password storage, emphasizing its direct pathway to account takeover and identity theft.
We observed a significant data leak impacting users of the "Figma Community" platform, discovered on or around December 21, 2023. The initial discovery revealed a substantial volume of sensitive information, including email addresses, usernames, and hashed passwords. What is particularly noteworthy is the presence of API keys and access tokens within the compromised dataset, suggesting a sophisticated attack vector that bypassed standard authentication mechanisms. The sheer scale and the inclusion of these highly sensitive programmatic credentials elevate this incident beyond a typical credential stuffing scenario.
The Figma Community breach appears to be a complex incident involving unauthorized access to internal systems. The leaked data encompasses approximately 2.7 million records, comprising email addresses, usernames, and hashed passwords. Crucially, the dataset also contains a significant number of API keys and access tokens, indicating a potential compromise of backend services or developer accounts. The source structure points towards a breach originating from an internal database or a staging environment that was not adequately secured. The leak locations are multifaceted, with initial reports suggesting distribution across multiple private channels and underground forums, indicating a deliberate effort to maximize impact and accessibility.
This breach has generated considerable attention in the cybersecurity community and the design industry. Several tech news outlets have reported on the incident, highlighting the potential implications for designers and organizations relying on Figma's collaborative tools. Security researchers have pointed to the presence of API keys as a particularly alarming aspect, suggesting that attackers could potentially gain programmatic access to user accounts or sensitive project data. While Figma has acknowledged the incident and initiated an investigation, the ongoing analysis of the leaked data and its potential exploitation remains a critical concern. Further investigation into the specific vulnerabilities exploited is ongoing.
Our analysis has identified a substantial data breach affecting "MyFitnessPal," a popular health and fitness tracking application. Discovered on or around April 25, 2018, the incident resulted in the exposure of millions of user records. What is particularly concerning is the breadth of personal health information compromised, in addition to standard account credentials. The fact that this data was subsequently made available on a dark web marketplace underscores the immediate threat to user privacy and the potential for misuse of sensitive health-related details.
The MyFitnessPal breach was a significant database compromise, impacting an estimated 150 million user accounts. The leaked data included a wide array of information, such as usernames, email addresses, and hashed passwords. More alarmingly, the breach also exposed dietary information, exercise logs, and other personally identifiable health data, making this a highly sensitive incident. The source structure suggests a direct infiltration of their primary user database. The leaked data was found to be circulating on a prominent dark web marketplace, indicating a commercial motive behind the data exfiltration and sale.
This breach garnered significant media coverage due to the sensitive nature of the data involved. Major news outlets reported extensively on the incident, emphasizing the potential privacy risks for users of health and fitness applications. Cybersecurity firms and researchers have analyzed the leaked data, highlighting the potential for this information to be used for targeted phishing attacks, blackmail, or even identity theft, particularly given the inclusion of health details. MyFitnessPal itself issued statements acknowledging the breach and outlining steps taken to address the vulnerability and notify affected users.
Breach Breakdown
14,903 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds