Inside the Mix 97 Breach: How 11,553 Records Were Compromised
Mix 97, the Canadian FM radio station serving Belleville and the Quinte region of Ontario, had its user database compromised in August 2018 when a dataset containing 11,553 account records ended up on a prominent hacking forum. Radio station websites are rarely thought of as high-value targets, but this breach is a reminder that any platform collecting user registrations is storing data that attackers will take if given the chance. The real problem here is that those passwords were stored in plaintext.
Why This Is Dangerous
Storing passwords in plaintext is one of the most serious security mistakes any platform can make. It means that when an attacker gets access to the database, they do not need to do any cracking or guessing. The actual passwords users typed are sitting right there in the file, ready to be used immediately against other accounts.
People who signed up for a Mix 97 account likely used the same email and password they use elsewhere. An attacker with 11,553 plaintext credentials does not see a radio station database, they see a set of master keys to test against Gmail, Outlook, Facebook, banking apps, and anywhere else those users have accounts. Even a 5 percent success rate translates into hundreds of compromised accounts on other platforms.
Canadian users are not immune from international cybercriminal activity. These datasets move fast once they hit the underground. A hacking forum post in 2018 could mean the data was downloaded by threat actors in dozens of countries within days, making it nearly imposible to contain once it was out.
What Was Exposed
- Email addresses
- Plaintext passwords
- Usernames or display names
- Account registration dates
- User profile information
- Location or region data
- Contest entry or listener preference data
Why This Matters
Regional media organizations like Mix 97 hold a trusted place in their communities. Listeners who created accounts to enter contests, request songs, or engage with local content trusted the station with their personal information. Having that trust betrayed through a data breach is a real harm, even if it does not make national headlines.
The breach also illustrates a systemic problem with smaller organizations that run websites as a secondary function of their core business. IT security is often not a priority, and outdated web platforms with poor credential storage practices are left running for years. This is how an entertainment site that stores local listener data ends up contributing to a global pool of stolen credentials that attackers recycle across campaigns for years.
How Combolist Breaches Work
A combolist breach starts with the theft of a database, typically through an SQL injection vulnerability, an exposed database port, or compromised admin credentials. Once the attacker has the database, they extract the user table and convert it into a simple list of email and password pairs. The Mix 97 database would have been converted into this format and shared or sold on hacking forums.
Combolists are then fed into credential stuffing tools that automaticly test each pair against popular login pages. These tools can process thousands of attempts per minute and are specifically designed to evade rate limiting and account lockout protections. The plaintext nature of the Mix 97 passwords made them immediately usable with no processing required.
Once credentials from one breach are confirmed to work on another platform, they often get re-packaged and shared again as a fresh "verified" combolist with an even higher success rate. This cycle means breach data rarely goes stale, it just gets recycled into progressively more targeted attacks.
Check If You Were Affected
If you ever created an account on the Mix 97 website to enter contests or access listener content, your credentials may be in this breach. Use HEROIC's free breach checker at heroic.com to scan your email address and find out if it appears in this or any other known data breach. If you get a hit, change every account that shares that password right away.
Breach Breakdown
11,553 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds