Breach Intelligence Report 12 Dec 2025

FLEX Editions

HEROIC
HEROIC Threat Intelligence Team
Email Address Password Hash Salt
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 6,562
Source Type Database,Combolist
Origin Darkweb
Password Type MD5(Salt)

We noticed a recent resurfacing of data attributed to FLEX Editions, a French e-commerce platform specializing in sheet music. The dataset, initially appearing in August 2018, has re-emerged on a prominent cybercrime forum, indicating potential reuse or renewed interest from threat actors. What struck us was the relatively small, yet specific, nature of the exposed credentials, suggesting a targeted compromise rather than a broad, indiscriminate sweep. The inclusion of both password hashes and their corresponding salts is a critical detail, providing attackers with the necessary components for offline brute-force or rainbow table attacks.

The breach, impacting 6,562 unique records, originated from a database compromise on the FLEX Editions platform. The exposed data primarily consists of email addresses and MD5 hashed and salted passwords. The presence of the salt is a significant factor, as it mitigates the effectiveness of pre-computed rainbow tables against common passwords, forcing attackers to dedicate more resources to cracking individual hashes. The data was initially disseminated on a well-known cybercrime forum, a common distribution point for compromised credential sets. The nature of the data suggests this breach could be leveraged for credential stuffing attacks against FLEX Editions or other services where users might have reused credentials.

While this specific FLEX Editions breach did not garner widespread mainstream news coverage at the time of its initial discovery in 2018, similar credential stuffing incidents are a persistent threat. Research from cybersecurity firms regularly highlights the prevalence of compromised credentials being traded and utilized on dark web marketplaces. The MD5 hashing algorithm, while considered weak by modern standards, is still frequently encountered in older or less security-conscious systems, making the recovery of these passwords a feasible endeavor for determined attackers.

Our attention was drawn to a recent aggregation of user data originating from a breach affecting "The Epoch Times" website, discovered in late 2019. The dataset, which has seen renewed activity on underground forums, contains a substantial volume of personally identifiable information. What is particularly concerning is the inclusion of not only basic contact details but also sensitive demographic and subscription-related information, painting a more detailed picture of the affected user base than typically seen in simpler credential dumps.

The Epoch Times breach, initially identified in November 2019, exposed the data of approximately 300,000 users. The compromised information includes email addresses, names, IP addresses, and password hashes (SHA1). Crucially, the breach also revealed geographic locations, subscription details, and inferred interests based on user activity. The SHA1 hashing algorithm, while an improvement over MD5, is still vulnerable to brute-force and dictionary attacks, especially when combined with readily available user information for targeted guessing. The data was found on a popular dark web marketplace, indicating its availability to a wide range of malicious actors. The thematic elements point towards potential phishing campaigns, targeted advertising, and further exploitation of user trust.

While the initial discovery of the Epoch Times breach was reported by several cybersecurity news outlets, the ongoing circulation and potential repurposing of this data underscore a broader trend. Research from organizations like the Identity Theft Resource Center consistently shows that data breaches, even those from several years ago, continue to be a significant source of compromised information used in subsequent attacks. The detailed user profiles within this dataset make it a valuable resource for sophisticated social engineering operations.

We've observed a new listing containing user data from "MyFitnessPal," a popular health and fitness tracking application, which was initially compromised in March 2018. This particular dataset, which has seen significant redistribution and analysis on various cybersecurity forums, stands out due to the sheer scale of the exposure and the inclusion of highly personal health-related information. What is particularly alarming is the potential for this data to be correlated with other breached datasets, creating highly detailed and potentially exploitable profiles of individuals.

The MyFitnessPal breach, first disclosed in March 2018, affected an estimated 150 million users. The exposed data includes email addresses, usernames, and password hashes (bcrypt). While bcrypt is a more robust hashing algorithm than MD5 or SHA1, it is not impervious to sophisticated attacks, especially with large volumes of data. The breach also included nutritional information, exercise logs, and demographic data, making it a treasure trove for attackers seeking to exploit personal health information. The data was widely distributed across multiple cybercrime forums and marketplaces, indicating a high level of accessibility. The threat themes associated with this breach include highly targeted phishing attacks, blackmail, and the potential for sale to entities interested in health-related consumer data.

This MyFitnessPal breach received considerable media attention at the time of its discovery, being one of the largest breaches of its kind. Subsequent analysis by security researchers has often highlighted the value of such detailed personal data in the underground economy. The ongoing availability and use of this dataset serve as a stark reminder of the long-term implications of health-related data breaches and the importance of robust security measures for applications handling sensitive personal information.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Password Hash,Salt
Password Types MD5(Salt)
Date Leaked 12 Dec 2025
Check in 5 seconds

6,562 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,692 scanned today
Breach Rank #N/A by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $47.5K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance