Breach Intelligence Report 25 Jul 2022

Fun Office Pools

HEROIC
HEROIC Threat Intelligence Team
First Name Last Hash Type Email Address Username Passwords
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 51,586
Source Type Database
Origin Telegram
Password Type plaintext(generated)

We've been tracking a resurgence of older database breaches appearing in aggregate dumps on various dark web forums. These aren't new attacks, but the re-emergence of credential sets from years past presents a persistent risk, especially when users recycle passwords across different services. What caught our attention with the **Fun Office Pools** data wasn't the size of the breach itself, but the relatively high proportion of valid-looking email addresses and the cleartext storage of some passwords alongside salted hashes. This combination increases the likelihood of successful credential stuffing attacks against other platforms.

The "Fun Office Pools" Leak: A Cautionary Tale From 2016 Resurfaces

The breach at Fun Office Pools, a website that allowed users to create and participate in online sports pools, originally occurred on April 1, 2016. The data, affecting 51,586 accounts, has recently been circulating more actively on underground forums and Telegram channels known for aggregating and trading breached databases. While the breach itself is not new, its reappearance highlights the long tail of risk associated with compromised credentials and the continued viability of older data in password reuse attacks.

The breach was discovered through our monitoring of known breach aggregation sites. The data dump stood out due to the presence of both hashed and unhashed passwords. While the majority of passwords were protected using hashing algorithms, the existence of any cleartext passwords significantly increases the risk to affected users, especially if they used those same passwords on other, more sensitive platforms. This suggests a lax security posture at the time of the breach.

The re-emergence of this data is concerning for enterprises because employees often use personal email addresses and recycled passwords for seemingly innocuous services like online games or sports pools. These compromised credentials can then be used to gain access to corporate resources through credential stuffing attacks, where attackers systematically try combinations of usernames and passwords across different login portals.

This incident serves as a reminder of the enduring threat posed by older breaches. It ties into the broader trend of attackers leveraging aggregated credential dumps to automate attacks against a wide range of targets. The availability of tools that can efficiently test millions of username/password combinations makes even relatively small breaches like this a potential source of significant risk.

  • Total records exposed: 51,586
  • Types of data included: First Name, Last Name, Email Address, Username, Passwords (both hashed and in cleartext)
  • Sensitive content types: PII
  • Source structure: Database
  • Leak location(s): Dark web forums, Telegram channels
  • Date leaked: 01-Apr-2016

Troy Hunt, the creator of Have I Been Pwned?, added the Fun Office Pools breach to his database in 2016, further validating its authenticity and impact. His site allows users to check if their email address has been compromised in known data breaches, providing a valuable resource for individuals and organizations to assess their risk exposure. The continued presence of this breach on Have I Been Pwned? underscores its lasting relevance.

Breach Breakdown

Domain N/A
Leaked Data First Name, Last Name, Hash Type, Email Address, Username, Passwords
Password Types plaintext(generated)
Date Leaked 25 Jul 2022
Check in 5 seconds

51,586 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,039 scanned today
Breach Rank #5,286 by affected users
Impact Score
2
sensitivity + scale + recency
Est. Financial Impact $373.3K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance