One Dark Web Listing. 316,633 Plaintext Passwords. The Fax Express Breach.
HEROIC analysts found a dataset linked to Fax Express, a US-based seller of fax machines, printers, and office equipment, circulating across dark web forums. The data was leaked on 06-May-2023 and covered 316,633 records. What made this breach stand out immediately was not just the volume but the content: plaintext passwords. No hashing, no encryption. Just raw credentials stored the way no company should ever store them, sitting in a dump file and ready for immediate use by anyone who downloaded it.
316,633 Plaintext Passwords: The Worst Case in the Fax Express Breach
Plaintext password storage means there is no cracking required. When this database was exfiltrated, attackers recieved the actual passwords typed by real users, in full. Those passwords were immediately usable. Credential stuffing tools could begin testing them against email providers, banks, and other services within minutes of the data going live. With over 316,000 records in a single dump, the scale of potential account takeover is significant.
What Was Exposed in the Fax Express Breach
- Email addresses
- Plaintext passwords
One Dark Web Listing. 316,633 Real Passwords Ready to Use.
The simplicity of this breach is what makes it so dangerous. Attackers do not need to be sophisticated to exploit a plaintext password dump. Anyone who can download a file and run a basic credential stuffing tool can cause real damage. For users who recieved the same password on multiple sites, which research consistently shows is the majority of people, a single breach like this can cascade into account takeovers across email, social media, and financial services simultaneously.
How Plaintext Password Breaches Work
When a company fails to hash passwords before storing them, those passwords are saved in readable form in the database. Any attacker who gains database access, through SQL injection, a misconfigured backup, or a compromised admin account, gets the passwords immediately with no additional work. There is no cracking step, no waiting, and no technical barrier. The seperate question of why companies still do this in 2023 is unfortunately still unanswered for many small and medium businesses that have not audited their authentication systems.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email against more than 400 billion compromised records, including data from the Fax Express breach. If your email was in this dump, you should change that password everywhere you used it right now.
Breach Breakdown
316,633 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds