Salts Included. The HoundDawgs Breach Exposed 43,007 User Records.
HEROIC analysts came across the HoundDawgs breach while reviewing a batch of torrent tracker databases that had recieved attention on dark web forums in late December 2017. HoundDawgs, a Danish torrent tracker community, had its database taken by an attacker who collected 43,007 user records. The exposed data went beyond simple login credentials and included IP addresses and cryptographic salts in addition to usernames, email addresses, and password hashes. Exposing salts alongside hashed passwords is a serious problem because it gives attackers a head start in cracking those hashes into readable passwords.
What Attackers Can Do With IP Addresses and Hashed Passwords
Having both a user's IP address and their password hash opens up more attack paths than a simple email-and-password dump. The IP address reveals a rough physical location and the internet provider a user relied on, which can be used to craft more convincing fraud attempts. At the same time, SHA1 hashes paired with exposed salts are accessable to cracking tools that can convert them back to the original passwords, which attackers then try on email, banking, and other platforms through credential stuffing.
What Was Exposed in the HoundDawgs Breach
- Email Address
- Password Hash
- Username
- IP Address
- Salt
Why Torrent Site Breaches Carry Extra Privacy Risk
People who use torrent tracking communities have an added reason to worry when a breach occurs. The combination of usernames, email addresses, and IP addresses from a torrent site can be used to connect an online identity to real-world activity. Identity theft and account takeover are the immediate risks, but financial fraud can follow when attackers crack passwords and gain access to accounts tied to the same email. The 43,007 HoundDawgs records remain in circulation and continue to be tested against active accounts by automated tools.
How a Database Breach Works
A database breach happens when an attacker exploits a weakness in a website's code or server configuration and gains direct access to the stored user data. Rather than attacking individual users one by one, the attacker copies the entire database in a single operation. The stolen records are then moved off-site and distributed through underground channels. Most victims never receive a direct notification and may not know their data was taken for months or years.
Check If Your Data Was Exposed
HEROIC offers a free breach scanner built on a database of over 400 billion records. Enter your email address to check whether your information appeared in the HoundDawgs breach or any other incident tracked by HEROIC. Take a minute now to find out where your data has been.
Breach Breakdown
43,007 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds