ID Technologies
We noticed a significant data leak originating from the online platform of ID Technologies, a Canadian research and development firm. The breach, discovered on August 26, 2018, exposed a substantial number of user credentials. What struck us was the relatively low number of unique records compromised, yet the presence of password hashes, which, even if MD5, still represent a direct risk to user accounts. The data's subsequent appearance on a well-known cybercrime forum indicates a clear intent for monetization or further exploitation.
The breach of ID Technologies' platform resulted in the exposure of 6,841 records, primarily consisting of email addresses and MD5 hashed passwords. This incident appears to be a direct database compromise, with the exfiltrated data later being distributed as a combolist. The use of MD5, while considered weak by modern standards, still poses a risk, especially if users have reused passwords across different services. The fact that this data surfaced on a public cybercrime forum suggests it could be leveraged for credential stuffing attacks against other platforms or for direct account takeovers.
While this specific breach did not garner widespread media attention at the time, it aligns with a broader trend of smaller, targeted data exfiltrations from niche technology firms. Research into similar incidents from 2018 reveals a consistent pattern of attackers targeting databases for user credentials, often with the intent of building combolists for sale or for use in automated attacks. The accessibility of MD5 hashing algorithms means that even this older hashing method can be cracked with sufficient resources, potentially revealing plaintext passwords for a portion of the compromised accounts.
Breach Breakdown
6,841 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds