Fun Office Pools
We've been tracking a resurgence of older database breaches appearing in aggregate dumps on various dark web forums. These aren't new attacks, but the re-emergence of credential sets from years past presents a persistent risk, especially when users recycle passwords across different services. What caught our attention with the **Fun Office Pools** data wasn't the size of the breach itself, but the relatively high proportion of valid-looking email addresses and the cleartext storage of some passwords alongside salted hashes. This combination increases the likelihood of successful credential stuffing attacks against other platforms.
The "Fun Office Pools" Leak: A Cautionary Tale From 2016 Resurfaces
The breach at Fun Office Pools, a website that allowed users to create and participate in online sports pools, originally occurred on April 1, 2016. The data, affecting 51,586 accounts, has recently been circulating more actively on underground forums and Telegram channels known for aggregating and trading breached databases. While the breach itself is not new, its reappearance highlights the long tail of risk associated with compromised credentials and the continued viability of older data in password reuse attacks.
The breach was discovered through our monitoring of known breach aggregation sites. The data dump stood out due to the presence of both hashed and unhashed passwords. While the majority of passwords were protected using hashing algorithms, the existence of any cleartext passwords significantly increases the risk to affected users, especially if they used those same passwords on other, more sensitive platforms. This suggests a lax security posture at the time of the breach.
The re-emergence of this data is concerning for enterprises because employees often use personal email addresses and recycled passwords for seemingly innocuous services like online games or sports pools. These compromised credentials can then be used to gain access to corporate resources through credential stuffing attacks, where attackers systematically try combinations of usernames and passwords across different login portals.
This incident serves as a reminder of the enduring threat posed by older breaches. It ties into the broader trend of attackers leveraging aggregated credential dumps to automate attacks against a wide range of targets. The availability of tools that can efficiently test millions of username/password combinations makes even relatively small breaches like this a potential source of significant risk.
- Total records exposed: 51,586
- Types of data included: First Name, Last Name, Email Address, Username, Passwords (both hashed and in cleartext)
- Sensitive content types: PII
- Source structure: Database
- Leak location(s): Dark web forums, Telegram channels
- Date leaked: 01-Apr-2016
Troy Hunt, the creator of Have I Been Pwned?, added the Fun Office Pools breach to his database in 2016, further validating its authenticity and impact. His site allows users to check if their email address has been compromised in known data breaches, providing a valuable resource for individuals and organizations to assess their risk exposure. The continued presence of this breach on Have I Been Pwned? underscores its lasting relevance.
Breach Breakdown
51,586 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds