FNI Works
We noticed a significant influx of data appearing on a prominent Telegram channel on October 28th, 2024, originating from a US-based platform identified as FNI Works. What struck us immediately was the sheer volume and the inclusion of sensitive user credentials, specifically bcrypt hashed passwords, alongside personally identifiable information (PII). The discovery process involved correlating the leaked data with known FNI Works user attributes, confirming its authenticity and scope. This event represents a substantial risk to the user base of FNI Works, given the nature of the compromised data and its public dissemination.
The breach, affecting approximately 92,000 records, was identified through routine monitoring of dark web and illicit data sharing platforms. Analysis of the leaked dataset reveals a comprehensive user profile, including 45,802 unique email addresses, full names, usernames, phone numbers, and physical addresses. The presence of bcrypt hashed passwords is a critical concern, as even hashed credentials can be vulnerable to offline attacks if weak hashing practices or insufficient salting were employed. The data appears to have been exfiltrated directly from a database, likely due to a direct database compromise or a vulnerability allowing unauthorized access to sensitive tables. The subsequent sharing on a Telegram channel amplifies the immediate threat landscape, making the data accessible to a wider range of malicious actors.
While specific news coverage regarding this particular FNI Works breach is limited at this time, the broader trend of data leaks from platforms utilizing similar database structures and storing user credentials is well-documented. Threat intelligence reports from organizations like Mandiant and CrowdStrike consistently highlight the exploitation of database vulnerabilities as a primary vector for large-scale data exfiltration. The method of distribution via Telegram channels is also a common tactic observed in numerous other breaches, facilitating rapid dissemination and monetization of stolen data. Further OSINT investigation into the Telegram channel may reveal additional context or attribution, but the immediate focus remains on the potential impact to FNI Works' user base and the necessary mitigation strategies.
Breach Breakdown
45,802 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds