FLEX Editions
We noticed a recent resurfacing of data attributed to FLEX Editions, a French e-commerce platform specializing in sheet music. The dataset, initially appearing in August 2018, has re-emerged on a prominent cybercrime forum, indicating potential reuse or renewed interest from threat actors. What struck us was the relatively small, yet specific, nature of the exposed credentials, suggesting a targeted compromise rather than a broad, indiscriminate sweep. The inclusion of both password hashes and their corresponding salts is a critical detail, providing attackers with the necessary components for offline brute-force or rainbow table attacks.
The breach, impacting 6,562 unique records, originated from a database compromise on the FLEX Editions platform. The exposed data primarily consists of email addresses and MD5 hashed and salted passwords. The presence of the salt is a significant factor, as it mitigates the effectiveness of pre-computed rainbow tables against common passwords, forcing attackers to dedicate more resources to cracking individual hashes. The data was initially disseminated on a well-known cybercrime forum, a common distribution point for compromised credential sets. The nature of the data suggests this breach could be leveraged for credential stuffing attacks against FLEX Editions or other services where users might have reused credentials.
While this specific FLEX Editions breach did not garner widespread mainstream news coverage at the time of its initial discovery in 2018, similar credential stuffing incidents are a persistent threat. Research from cybersecurity firms regularly highlights the prevalence of compromised credentials being traded and utilized on dark web marketplaces. The MD5 hashing algorithm, while considered weak by modern standards, is still frequently encountered in older or less security-conscious systems, making the recovery of these passwords a feasible endeavor for determined attackers.
Our attention was drawn to a recent aggregation of user data originating from a breach affecting "The Epoch Times" website, discovered in late 2019. The dataset, which has seen renewed activity on underground forums, contains a substantial volume of personally identifiable information. What is particularly concerning is the inclusion of not only basic contact details but also sensitive demographic and subscription-related information, painting a more detailed picture of the affected user base than typically seen in simpler credential dumps.
The Epoch Times breach, initially identified in November 2019, exposed the data of approximately 300,000 users. The compromised information includes email addresses, names, IP addresses, and password hashes (SHA1). Crucially, the breach also revealed geographic locations, subscription details, and inferred interests based on user activity. The SHA1 hashing algorithm, while an improvement over MD5, is still vulnerable to brute-force and dictionary attacks, especially when combined with readily available user information for targeted guessing. The data was found on a popular dark web marketplace, indicating its availability to a wide range of malicious actors. The thematic elements point towards potential phishing campaigns, targeted advertising, and further exploitation of user trust.
While the initial discovery of the Epoch Times breach was reported by several cybersecurity news outlets, the ongoing circulation and potential repurposing of this data underscore a broader trend. Research from organizations like the Identity Theft Resource Center consistently shows that data breaches, even those from several years ago, continue to be a significant source of compromised information used in subsequent attacks. The detailed user profiles within this dataset make it a valuable resource for sophisticated social engineering operations.
We've observed a new listing containing user data from "MyFitnessPal," a popular health and fitness tracking application, which was initially compromised in March 2018. This particular dataset, which has seen significant redistribution and analysis on various cybersecurity forums, stands out due to the sheer scale of the exposure and the inclusion of highly personal health-related information. What is particularly alarming is the potential for this data to be correlated with other breached datasets, creating highly detailed and potentially exploitable profiles of individuals.
The MyFitnessPal breach, first disclosed in March 2018, affected an estimated 150 million users. The exposed data includes email addresses, usernames, and password hashes (bcrypt). While bcrypt is a more robust hashing algorithm than MD5 or SHA1, it is not impervious to sophisticated attacks, especially with large volumes of data. The breach also included nutritional information, exercise logs, and demographic data, making it a treasure trove for attackers seeking to exploit personal health information. The data was widely distributed across multiple cybercrime forums and marketplaces, indicating a high level of accessibility. The threat themes associated with this breach include highly targeted phishing attacks, blackmail, and the potential for sale to entities interested in health-related consumer data.
This MyFitnessPal breach received considerable media attention at the time of its discovery, being one of the largest breaches of its kind. Subsequent analysis by security researchers has often highlighted the value of such detailed personal data in the underground economy. The ongoing availability and use of this dataset serve as a stark reminder of the long-term implications of health-related data breaches and the importance of robust security measures for applications handling sensitive personal information.
Breach Breakdown
6,562 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds