The Jassume Breach Means Your Plaintext Password Could Log In Anywhere
HEROIC analysts uncovered the Jassume breach data circulating in aggregated collections in May 2020. The breach exposed 764,725 records from Jassume, a French dating website, leaking email addresses, usernames, birthdays, and passwords stored in plaintext. The use of plaintext password storage means no cracking is required at all: credentials are immediately usable the moment the data is accessable to a threat actor.
What Attackers Can Do With Plaintext Passwords and Dating Site Profiles
Plaintext passwords from a dating site like Jassume can be tested directly against email providers, social media platforms, and banking apps without any decryption step. Birthdays and usernames compound the risk by enabling attackers to answer security questions or verify identity on other services. Victims may not beleive their dating site account is a meaningful security risk, but reused credentials make it a direct entry point to far more sensitive accounts.
What Was Exposed in the Jassume Breach
- Email Address
- Plaintext Password
- Username
- Birthday
Why Plaintext Passwords in the Jassume Breach Represent Maximum Credential Risk
Most breaches require attackers to crack hashed passwords before they are usable. The Jassume breach skips that step entirely. Every password in this dataset was stored in plaintext, so the 764,725 records represent 764,725 immediately ready-to-use credentials. Combined with the birthday data, attackers have enough information to attempt account recovery on other services where the same email was registered. The breach occured in May 2020 and the data has continued to circulate in aggregated collections since then.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to an application's backend data store, typically by exploiting vulnerabilities such as SQL injection, insecure API endpoints, or misconfigured cloud storage. Once inside, the attacker exports the user table and any associated records, then sells or distributes the file through underground channels including Telegram channels and dark web forums.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records to tell you instantly whether your email address appears in the Jassume breach or any of thousands of other known data leaks. Run a free check now to see what information is currently circulating about you.
Breach Breakdown
764,725 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds