Institute of Chartered Accountants of Nepal
We noticed the public dissemination of credentials originating from the Institute of Chartered Accountants of Nepal (ICAN) on August 21, 2018. This incident, which surfaced on a well-known hacking forum, exposed a significant volume of user data. What struck us immediately was the nature of the compromised credentials – specifically, the presence of plaintext passwords alongside email addresses. This lack of even basic hashing is a critical vulnerability that dramatically increases the risk of credential stuffing attacks against ICAN's users and potentially other services they may reuse credentials on.
The breach, affecting approximately 10,260 records, primarily comprised email addresses and their associated plaintext passwords. Analysis of the leaked data structure suggests a direct database dump or a similarly unencrypted export from ICAN's platform. The exposure of credentials in such a raw format is particularly concerning, as it bypasses any authentication layer that might have been expected. This type of data is a prime commodity for threat actors seeking to gain unauthorized access to accounts through automated brute-force or dictionary attacks, especially if users have exhibited password reuse across different online services. The leak location on a public forum amplifies the immediate threat, making the data readily accessible to a wide range of malicious actors.
While this specific incident from 2018 may not have generated widespread mainstream news coverage at the time, the underlying vulnerability of storing plaintext passwords is a recurring theme in cybersecurity. Numerous data breach reports and security advisories consistently highlight this as a fundamental security flaw. Organizations like the SANS Institute and OWASP have long emphasized the critical need for proper password hashing and salting as a baseline security control. The ICAN breach serves as a stark reminder of the persistent risks associated with inadequate data protection practices, even for seemingly niche or professional organizations.
Breach Breakdown
10,260 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds