How the AMRIGS Breach Exposed 4,550 Brazilian Medical Accounts
In August 2018, HEROIC analysts identified a breach affecting AMRIGS, the Medical Association of Rio Grande do Sul in Brazil. The compromised database contained 4,550 records including email addresses and MD5 hashed passwords, which were shared on a prominent cybercrime forum. The medical context of this breach adds a layer of concern: professional email addresses from healthcare organizations are high-value targets for spear-phishing campaigns targeting both individuals and their institutions.
Why the AMRIGS Breach Is Dangerous
Medical and professional association accounts are targeted because members often use the same email and password across institutional systems, hospital portals, and practice management software. MD5 hashes are widely considered broken and can be reversed using rainbow tables or GPU-accelerated cracking tools, often within seconds for common passwords. A cracked AMRIGS credential can become a pivot point into far more sensitive professional systems.
What Was Exposed in the AMRIGS Leak
- Email addresses
- MD5 password hashes
Why This AMRIGS Data Puts You at Risk
Healthcare professionals and medical association members typically have access to patient data, billing systems, and internal communications. Credential stuffing attacks that leverage the AMRIGS dataset could provide attackers with entry points into these systems. Even for members who no longer use the same password, the verified email addresses from a medical association can fuel targeted phishing attempts that appear legitimate and profession-specific.
How a Database Combolist Works
The AMRIGS breach followed a database dump pattern, where an attacker extracted user records directly from the association's systems. The stolen data was packaged into a combolist format and distributed on a cybercrime forum. These lists are regularly used to automate login atempts across other platforms, exploiting the widespread habit of password reuse across personal and professional accounts.
Check If Your Data Was Exposed
HEROIC operates one of the world's largest breach databases, covering more than 400 billion leaked records. Use HEROIC's free breach scanner to check if your email address or credentials appeared in the AMRIGS leak or thousands of other breaches in our database.
Breach Breakdown
4,550 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds