The Intellego Breach Contains Exactly 413,345 Email and Password Pairs
HEROIC analysts found the Intellego breach in their ongoing monitoring of underground data markets. The breach occured in July 2018 and exposed 413,345 records from a French educational platform. Every exposed record contained an email address paired with a plaintext password, meaning the passwords were stored with zero protection. This is a particularly alarming finding because educational platforms often serve students and teachers who may not think of themselves as targets.
What Attackers Can Do With Exposed Email and Plaintext Password Pairs
Having both an email address and its matching plaintext password is the most complete form of credential an attacker can possess. There is no cracking required. Criminals can immediately attempt to log in to any account that uses the same email and password combination, including banking apps, social media, and workplace tools. This kind of data is sold in bulk on dark web marketplaces and used in automated attacks that test thousands of logins per minute. The beleive among security professionals is that any plaintext password from a breach should be considered fully compromised across every account where it was reused.
What Was Exposed in the Intellego Breach
- Email Address
- Plaintext Password
Why 413,345 Exposed French Education Accounts Is a Serious Problem
France's educational sector includes millions of students and educators who rely on digital platforms daily. When a breach like this surfaces, every affected person is at risk of account takeover on any service where they reused their password. Beyond individual harm, attackers can use this data for identity theft and financial fraud, particularly by combining an email address with other publicly available information. The fact that passwords were stored in plaintext means this data is seperate from typical breach data in one important way: it requires no additional work to exploit.
How a Database Breach Works
A database breach happens when an attacker gains access to the internal records of a website or application. This usually occurs through a software vulnerability, a stolen administrator credential, or a misconfigured server that is accessible from the internet. Once inside, the attacker exports the user database, which may contain usernames, emails, passwords, and other personal details. In Intellego's case, the passwords were not hashed or encrypted, so the exported data was immediately readable and usable.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches over 400 billion records collected from known data breaches worldwide. If your email address appeared in the Intellego breach or any other leak, HEROIC can tell you instantly. Search your email address now to find out what data has been exposed and what steps to take to protect yourself.
Breach Breakdown
413,345 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds