ICSE Guess
We noticed a recent resurfacing of credentials originating from the defunct Indian educational platform, ICSE Guess. The data, initially leaked in August 2018, has reappeared on a prominent cybercrime forum, indicating potential reuse or renewed interest from malicious actors. What struck us was the **plaintext storage of passwords**, a critical vulnerability that significantly amplifies the risk associated with this exposure. The breach, affecting over 17,000 records, presents a clear and present danger for credential stuffing attacks, particularly against users who have historically reused credentials across different platforms.
The ICSE Guess data breach, discovered on August 21, 2018, involved a direct database compromise. A total of 17,276 unique records were exfiltrated, containing sensitive user information. The leaked data types are primarily email addresses and plaintext passwords. This combination is a potent recipe for account takeover. The source structure points to a direct extraction from the platform's primary user database. The information was subsequently posted on a well-known cybercrime forum, making it readily accessible to a wide range of threat actors. The fact that the platform is now defunct does not diminish the threat; rather, it suggests that these credentials may still be active on other, currently operational services, especially if users have not updated their passwords since the initial compromise.
While specific news coverage of the initial ICSE Guess breach in 2018 was limited, the reappearance of such data on cybercrime forums is a consistent theme in the threat landscape. OSINT investigations into similar breaches often reveal patterns of credential reuse. Research by organizations like Troy Hunt (Have I Been Pwned) consistently highlights the dangers of plaintext password storage, emphasizing that even outdated breaches can remain highly relevant due to user inertia in updating security practices. The current posting on a cybercrime forum places this data squarely within the realm of active exploitation, likely for automated credential stuffing campaigns targeting various online services.
Breach Breakdown
17,276 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds