The go4oilgasandenergyjobs Dump: 171K Plaintext Passwords Exposed
HEROIC analysts recieved intelligence on a data breach tied to go4oilgasandenergyjobs, a now-defunct U.K.-based recruitment platform for the global Oil, Gas and Energy sector. The incident dates to August 2018 and affected 171,274 user accounts. Exposed records contained email addresses and plaintext passwords, meaning the site stored credentials with zero cryptographic protection. The data has been circulating in dark web compilations targeting recruitment platform databases.
Plaintext Passwords: The Most Dangerous Credential Exposure
When attackers obtain plaintext passwords, no cracking is required. They can immediately use those credentials in automated login attempts across banking, email, and social media platforms. Because many users reuse passwords, a single recruitment site breach becomes accessable to attackers as a master key to dozens of other accounts. The oil and gas sector context also means some affected users likely hold privileged access to industrial systems.
What Was Exposed in the go4oilgasandenergyjobs Breach
- Email Address
- Plaintext Password
Why Plaintext Credential Leaks Cause Lasting Damage
Credential stuffing attacks powered by plaintext passwords are partcularly effective because they require no additional processing. Cybercriminals run automated tools against hundreds of sites simultaneously, achieving account takeover at scale. Identity theft and financial fraud follow quickly when attackers gain access to email accounts and use them for password resets on banking and investment platforms. Even seven years after this breach, the credentials remain a live threat for anyone who has not changed their passwords.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a site's backend data store, typically by exploiting unpatched software vulnerabilities, weak administrative credentials, or SQL injection flaws. Once inside, attackers export user tables containing account information. In cases like go4oilgasandenergyjobs, the absence of password hashing meant the exported data required no further processing before being weaponized.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion records to tell you instantly whether your email address appears in the go4oilgasandenergyjobs breach or thousands of other known incidents. Run a free scan at HEROIC.com to find out what data of yours is circulating on the dark web and take action before attackers do.
Breach Breakdown
171,274 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds