If Your AMResorts Password Was Reused, Other Accounts May Be at Risk
In August 2018, HEROIC analysts identified 12,007 records from AMResorts, a now-defunct US-based hospitality platform, posted on a prominent cybercrime forum. The exposed dataset included email addresses and MD5 hashed passwords. Even years after the platform shut down, credentials like these continue to circulate in combolists and fuel attacks against other services where users recycled the same password.
Why the AMResorts Breach Is Dangerous
MD5-hashed passwords can be cracked with modern hardware in minutes or seconds when the underlying password is short, common, or simple. Once cracked, attackers pair the recovered password with the corresponding email address and test it across banking apps, email providers, and streaming services. The defunct status of AMResorts means users are unlikely to receive a breach notification or a prompt to change their credentials, leaving them exposed indefinitely.
What Was Exposed in the AMResorts Leak
- Email addresses
- MD5 password hashes
Why This AMResorts Data Puts You at Risk
If your AMResorts password was reused elsewhere, other accounts may be at risk right now. Cybercriminals incorporate datasets like this one into automated credential stuffing tools that can test thousands of login combinations per minute across hundreds of websites. Hospitality and travel platform credentials are particularly valuable because many users create accounts with the same passwords they use for airline reward programs, hotel loyalty apps, and booking services.
How a Database Combolist Works
The AMResorts breach originated from a direct database extraction, where an attacker gained access to the platform's user database and exfiltrated records in bulk. The resulting data was formatted into a combolist, pairing email addresses with their hashed passwords, and shared on cybercrime forums for use in automated attacks. Combolists from defunct platforms are especially persistant because users rarely think to change passwords for services they no longer actively use.
Check If Your Data Was Exposed
HEROIC operates one of the world's largest breach databases, covering more than 400 billion leaked records. Use HEROIC's free breach scanner to check if your email address or credentials appeared in the AMResorts leak or thousands of other breaches in our database.
Breach Breakdown
12,007 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds