FunFiles
We noticed a recently surfaced dataset originating from FunFiles, a defunct German file-sharing service, which experienced a significant data compromise back in August 2018. The leak, which has now become publicly available on a prominent hacking forum, contains a substantial number of user credentials. What struck us was the resurfacing of this older breach data, potentially indicating a re-emergence of compromised credentials into the threat actor ecosystem, even years after the initial incident.
The FunFiles breach, initially reported in August 2018, impacted approximately 8,724 unique records. The compromised data primarily consists of email addresses and associated password hashes. Notably, the hashing algorithms employed were a mix of SHA1 and PHPass, presenting a varying level of cryptographic strength. This dataset was discovered being disseminated on a well-known underground forum, suggesting its potential use in credential stuffing attacks or for sale to other malicious actors. The nature of the breach appears to be a direct database compromise, with the leaked information subsequently compiled into a readily usable format for attackers.
While the FunFiles incident itself did not garner widespread mainstream media attention at the time of its discovery in 2018, its reappearance aligns with broader trends of historical data breaches being repackaged and exploited. The use of older hashing algorithms like SHA1, while less secure than modern standards, can still be vulnerable to brute-force or dictionary attacks, especially when combined with common password practices. The availability of such datasets on forums underscores the persistent threat posed by credential reuse across different online services.
Breach Breakdown
8,724 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds