HowtoCallAbroad
We noticed a recent resurfacing of credentials from a 2018 incident involving HowtoCallAbroad. While the initial leak occurred several years ago, the continued availability and potential repurposing of these credentials present an ongoing risk. What struck us was the relatively small number of affected users, 7,049, yet the presence of password hashes, even if salted, warrants a closer look at the potential for credential stuffing attacks against related services.
The breach, initially discovered on August 26, 2018, involved a database compromise at HowtoCallAbroad, a website providing free international calling information. The leaked dataset contained 7,049 records, comprising email addresses and phpass password hashes. This type of hash, while not plain text, is susceptible to brute-force attacks and rainbow table lookups, especially if weak passwords were used. The threat theme here is primarily credential reuse and the potential for attackers to leverage these compromised credentials for unauthorized access to other online accounts where users have exhibited poor password hygiene.
While this specific HowtoCallAbroad breach did not garner significant mainstream news coverage at the time, it aligns with a broader trend of smaller, niche websites becoming targets for data exfiltration. The presence of such datasets on hacking forums, even years after the initial compromise, underscores the persistent threat of data aggregation and its subsequent exploitation. Security researchers have consistently highlighted the dangers of password reuse, and incidents like this serve as a stark reminder of the long tail of data breach impacts.
Breach Breakdown
7,049 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds