Your Data May Be Out There. The FlyInside Breach Exposed 22K Users.
On January 1st, 2022, a database breach at FlyInside, a U.S.-based online service that helps real estate professionals create virtual property tours, quietly exposed 22,394 user records. The breach recieved no widespread attention, but for the affected users the consequences are real: both email addresses and passwords were leaked in plaintext, meaning anyone with access to the dataset can immediately attempt to use those credentials to access other accounts without any additional effort.
What Attackers Can Do With FlyInside's Plaintext Passwords
Plaintext passwords require zero cracking. Attackers who obtain this dataset can immediately run credential stuffing tools that test each email and password pair across hundreds of services simultaneously -- email, banking, social media, real estate platforms, and more. Real estate professionals in particular may have access to sensitive client data, property listings, and financial records on other platforms, making the downstream risk from this breach partcularly serious.
What Was Exposed in the FlyInside Breach
- Email Address
- Plaintext Password
Why Even Small Breaches Like FlyInside Matter
With only 22,394 records, this is a relatively small breach by volume. But credential datasets like this one are regularly combined with data from other leaks to build comprehensive user profiles. A user's password from FlyInside, combined with their name and phone number from another breach, gives attackers everything they need for targeted phishing or account takeover attacks that appear highly credible.
How a Database Breach Works
A database breach occurs when unauthorized access is gained to a web application's backend data store. Attackers may exploit SQL injection flaws, use compromised admin credentials, or take advantage of exposed database endpoints. Once inside, exporting a full user table takes seconds. Storing passwords in plaintext rather than using a strong hashing algorithm like bcrypt or Argon2 means that once the database is accessed, user credentials are immediately available to attackers with no further processing required.
Check If Your Data Was Exposed
HEROIC's Dark Web Monitor has indexed over 400 billion leaked records, including data from the FlyInside breach. Search your email address now to find out if your credentials have been compromised and get guidance on securing your accounts right away.
Breach Breakdown
22,394 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds