Hungry for Hits
We noticed a recent resurgence of activity surrounding a data leak originating from "Hungry for Hits," a Swedish advertising platform. The initial breach, dating back to August 26, 2018, has resurfaced, prompting a review of its implications. What struck us was the continued relevance of these credentials, even after several years, highlighting the persistent threat of credential stuffing attacks leveraging older, compromised datasets. The exposure of email addresses alongside bcrypt hashed passwords presents a clear vector for further compromise if these hashes are weak or if users have reused credentials.
The "Hungry for Hits" incident, first reported in late August 2018, involved the compromise of approximately 7,000 records. Of these, 5,564 unique email addresses were exposed, paired with their corresponding bcrypt password hashes. The data was subsequently disseminated on a well-known hacking forum, indicating a deliberate effort to monetize or distribute the compromised information. The breach type is categorized as a database compromise, leading to the creation of a combolist – a common tactic used by threat actors to facilitate brute-force or credential stuffing attacks against other online services. The presence of bcrypt, while a stronger hashing algorithm than MD5 or SHA-1, still poses a risk if weak passwords were used or if the hashing process itself had vulnerabilities.
While this specific breach from 2018 did not generate significant mainstream news coverage at the time, its reappearance is consistent with broader trends observed in OSINT investigations. Threat intelligence reports frequently detail how older, seemingly forgotten data dumps continue to be weaponized. Researchers have consistently documented the efficacy of credential stuffing attacks, where attackers use leaked username/password pairs to gain unauthorized access to other platforms. The "Hungry for Hits" data is a prime example of a dataset that, while old, remains a valuable resource for attackers seeking to exploit password reuse across the internet.
Breach Breakdown
5,564 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds