Dark Web Intel: 14,782 Find a Carer Login Credentials Exposed
HEROIC analysts flagged a dataset tied to Find a Carer, an Australian platform used to connect families with carers and support workers, while monitoring dark web hacking forums. The breach itself dates back to February 7, 2018, and the data has continued to resurface in aggregated leak collections since then. In total, 14,782 records were exposed, each containing an email address and an MD5 hashed password.
Why This Is Dangerous
MD5 hashed passwords offer little real protection today. The algorithm runs fast enough that attackers can crack large batches of hashes using GPU based tools or precomputed rainbow tables, recovering the original plaintext password behind each hash. Once cracked, the recovered password is already paired with a real email address, giving an attacker a ready made login credential to test elsewhere.
What Was Exposed
- Email addresses
- Password hashes (MD5)
Why This Matters
Find a Carer connects families with people who provide care in their homes, which means its users likely include people managing sensitive family circumstances. While the breach did not expose financial or health details directly, the real risk comes from password reuse. If a user's Find a Carer password matches the one they use for email, banking, or other accounts, a cracked credential from this leak can be used in credential stuffing attacks, automated attempts to log into other services with the same pair. That can lead to account takeover, identity theft, and financial fraud well beyond the original platform.
How Old Breaches Keep Fueling Dark Web Credential Lists
This incident fits the pattern of a direct database compromise, with the stolen records later surfacing on a hacking forum where they can be freely downloaded. Once in circulation, data like this is typically reformatted into a combolist, a stripped down file of email and password pairs used specifically for credential stuffing. Because MD5 hashes can be cracked in bulk, old breaches like this one continue to feed those combolists years after the original incident, which is why a leak from 2018 is still worth checking today.
Check If You Are Affected
If you ever used Find a Carer, or reused that account's password somewhere else, it is worth checking now rather than waiting. HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including this one, and shows you exactly what was exposed so you can secure any reused passwords.
Breach Breakdown
14,782 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds