The Horticultural News Breach Put 35,951 Names and Passwords Online
HEROIC analysts identified a breach connected to Horticultural News, a Kenya-based agriculture site at hortinews.co.ke, that exposed 35,951 user records. The breach dates back to November 23, 2015, and the exposed data set includes first names, last names, email addresses, and passwords hashed with MD5.
Why the Horticultural News Breach Is Dangerous Beyond Just Passwords
MD5 is an outdated hashing algorithm that can be cracked quickly with widely available tools, so the passwords in this breach should be treated as effectively exposed. But even without cracking a single password, the combination of full names and email addresses is valuable on its own. It gives attackers everything they need to craft convincing, personalized phishing emails that impersonate colleagues, suppliers, or the Horticultural News site itself.
What Was Exposed in the Horticultural News Breach
- First names
- Last names
- Email addresses
- Passwords (MD5 hashed)
Why This Matters for Horticultural News Readers
Once cracked, these passwords can be tested against other accounts through automated credential stuffing attacks, putting email, banking, and social media logins at risk if the password was reused. Separately, the full names paired with email addresses make this data useful for targeted phishing, since a message that uses your real name feels far more legitimate than a generic scam email.
How a Database Breach Like This Happens
A database breach like this one typically starts when attackers find a vulnerability in a website's software or server configuration and use it to gain access to the backend database. From there, they export the full set of user records, including names, emails, and hashed passwords, and distribute the file through hacking forums or private channels. That data can then sit and circulate quietly for years before resurfacing, as happened here roughly a decade after the original breach.
Check If You Are Affected
With nearly 36,000 records exposed, this breach still represents a meaningful pool of credentials and personal information that could be used in attacks today. HEROIC's free breach scanner checks your email address against a database of more than 400 billion leaked records, including this one, so you can find out in seconds whether your information was exposed and take steps to protect your accounts.
Breach Breakdown
35,951 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds