InterfaceLIFT Data Breach: 120,195 Plaintext Passwords Exposed
120,000 Reasons Not to Store Passwords in Plaintext
InterfaceLIFT built one of the internet's most populer desktop wallpaper repositories -- millions of high-resolution images, a thriving community of designers and photographers, and 120,195 registered users who trusted the site with their account credentials. That trust was violated in August 2018 when the site's user database appeared in underground circulation, every password stored in raw plaintext, readable by anyone who downloaded the file.
InterfaceLIFT (August 2018): Breach Summary
- Records Exposed: 120,195
- Data Types: Email addresses, usernames, passwords (Plaintext)
- Breach Type: Database, Combolist
- Country Affected: United States
- Date Leaked: August 21, 2018
Plaintext Passwords: The Worst Possible Outcome
In the spectrum of password storage failures, plaintext is the absolute bottom. There is no hashing to reverse, no salt to work around, no algorithm to crack. When InterfaceLIFT's databse was breached, every single user's password was immediately usable -- not as a hash to be processed, but as a literal string ready for direct login attempts. This means any attacker who obtained the dump could immediately begin credential stuffing attacks across every major platform: Gmail, Facebook, LinkedIn, banking sites, cloud storage. The question was never whether these credientials could be compromised -- they already were, the moment someone downloaded the file.
The Credential Stuffing Multiplier
120,195 accounts is a significant breach volume by any measure, and the plaintext nature amplifies the risk exponentially. Studies consistently show that 40-60% of users reuse passwords across multiple sites. With plaintext credentials in hand, automated credential stuffing tools can test all 120K email/password pairs against hundreds of platforms simultaneously within hours. For users who registered with a work email and reused their corporate password on InterfaceLIFT -- a scenario security researchers see constantly -- the consequences extend well beyond a compromised wallpaper account into full business email takeover territory.
Part of the August 2018 Combolist Wave
The August 21, 2018 date places InterfaceLIFT within a broader wave of simultaneous breach disclosures across August 2018. Multiple platforms across the US, Asia, and Europe saw their data surface within a compressed timeframe, consistent with a threat actor releasing accumulated material in bulk. At 120,195 records, InterfaceLIFT represents one of the larger individual contributions to this wave -- plaintext passwords included, making it among the most immediately dangerous dumps in the cluster.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records to tell you exactly which of your accounts have been compromised. If you ever registered on InterfaceLIFT, check now at HEROIC.com -- because plaintext passwords from 2018 are still being actively used in credential stuffing campaigns today.
Breach Breakdown
120,195 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds