Hostinger
We've been tracking a resurgence in older breaches, often resurfacing in aggregated credential stuffing lists. What caught our attention wasn't the size of this particular leak, but the fact that credentials from a 2015 Hostinger breach are still actively circulating and being used in attempts to compromise accounts across various platforms. The longevity of these exposed credentials highlights the persistent risk posed by older breaches and the importance of proactive password resets. The fact that passwords were stored in plaintext is a major red flag.
The 2015 Hostinger Breach: Plaintext Passwords Still in Play
In late December 2015, web hosting provider Hostinger suffered a significant data breach. It was discovered following reports of unusual activity and user complaints. The breach exposed nearly 1 million user records, containing sensitive information including email addresses, usernames, IP addresses, and, most critically, passwords stored in plaintext. This lack of password hashing or salting made the exposed credentials particularly vulnerable to misuse. The data has since been observed on various underground forums and credential stuffing lists.
The continued relevance of this breach stems from the fact that many users reuse passwords across multiple services. Even years after the initial breach, these credentials can still be used to gain unauthorized access to user accounts on other platforms. This highlights the importance of unique, strong passwords for each online account and the dangers of password reuse.
- Total records exposed: 998,676
- Types of data included: Email Addresses, Plaintext Passwords, Usernames, IP Addresses
- Source structure: Database
- Leak location(s): Various hacking forums, credential stuffing lists, and dark web marketplaces.
- Date of first appearance: December 31, 2015
Troy Hunt, creator of Have I Been Pwned, added the Hostinger breach to his database in January 2016, confirming the scale and scope of the incident. Many users can check if their email address was exposed in the breach via his website. The fact that this breach is still actively tracked in such databases underlines its continued relevance.
Breach Breakdown
998,676 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds