Funada
We noticed a new entry on a well-known dark web forum detailing a breach impacting the Brazilian beverage company, Funada. The leak, dated August 26, 2018, surfaced approximately three years after the initial compromise. What struck us was the relatively low volume of records (10,426) for a public-facing platform, suggesting either a targeted attack or a limited scope of compromised user accounts. The inclusion of MD5 hashed passwords, while a weaker hashing algorithm, still presents a risk of credential stuffing if not properly managed by users.
The Funada breach appears to stem from a direct database compromise. The exposed data consists of 10,426 unique records, each containing an email address and an MD5 hashed password. The data was found disseminated on a popular hacking forum, indicating it was likely sold or shared for malicious purposes. The threat theme here is primarily credential reuse and potential account takeover. While MD5 is considered cryptographically broken, its continued use in older systems or by less security-conscious users makes these hashes a valuable commodity for attackers looking to leverage password spraying or dictionary attacks against other platforms where users might have reused credentials.
At the time of the leak in August 2018, there was no significant mainstream news coverage regarding a breach of Funada. However, the nature of the leak – appearing on a hacking forum – aligns with common patterns of data exfiltration and sale. Security researchers have long warned about the prevalence of MD5 hashed passwords in older databases and the associated risks. This incident serves as a reminder of the ongoing threat posed by legacy systems and the importance of robust password hashing and salting practices, even for seemingly less high-profile organizations.
Breach Breakdown
10,426 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds