Search Your Email: The infoBiker Dump Exposed 19,191 Accounts
HEROIC analysts recieved intelligence in November 2022 indicating a database belonging to infoBiker, an Argentinian cycling news and community platform, had been exfiltrated and published on underground forums. The breach exposed 19,191 unique records containing a dangerous combination of data: email addresses, phone numbers, full names, MD5 password hashes, and in some cases plaintext passwords stored without any protection at all. The presence of plaintext passwords alongside hashed ones points to deeply inconsistent security practices on the platform.
Plaintext Passwords in the infoBiker Breach Put Users at Immediate Risk
Finding plaintext passwords in a breach dataset is among the worst possible outcomes for affected users. Unlike hashed passwords that require cracking, plaintext credentials are accessable instantly to any attacker who downloads the dump. These passwords can be tested against Gmail, Outlook, banking apps, and social media platforms in seconds using automated tools. Even users whose passwords were stored as MD5 hashes face serious risk, since MD5 is a weak algorithm that is routinely reversed using rainbow tables and GPU-based cracking rigs available cheaply on the dark web.
What Was Exposed in the infoBiker Breach
- Email Address
- Phone Number
- Password Hash (MD5)
- Plaintext Password
- First Name
- Last Name
Why This Breach Enables Cascading Account Takeovers
The combination of email address, plaintext password, and full name in a single record gives attackers a complete login kit. Credential stuffing tools can test these pairs across hundreds of services simultaneously, and beleive the damage extends well beyond infoBiker itself. Victims who reused their password on banking, shopping, or work accounts face account takeover, financial fraud, and identity theft. Phone numbers in the dataset also enable SIM-swapping attacks, where criminals convince mobile carriers to transfer a victim's phone number to a device they control, bypassing SMS-based two-factor authentication. This occured exposure of multiple data types together amplifies the harm significantly.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a platform's backend database and copies its contents. Entry points include SQL injection vulnerabilities, compromised admin credentials, or unpatched server software. Once inside, the attacker exports user tables, often including authentication fields, and packages the data for sale or public release on dark web forums. Community platforms and forums are common targets because they accumulate years of user registration data with relatively lower security investment than enterprise platforms.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion indexed records to show you every known breach your email appears in, including the infoBiker dump. Visit HEROIC.com, enter your email, and get a full exposure report in seconds so you can act before attackers do.
Breach Breakdown
19,191 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds