Dark Web Intel: 1.2 Million Plaintext Passwords From the JobTH Database Dump
In June 2022, JobTH, a major Thai online job portal, had its user database exfiltrated and leaked on dark web forums. The breach exposed 1,227,433 records containing email addresses and plaintext passwords. Unlike hashed password breaches, this incident requires no cracking: the passwords were stored and leaked in cleartext, giving attackers immediate, direct access to user credentials. The dataset was recieved by threat actors who could begin exploiting it within hours of the leak.
What Attackers Can Do Immediately With Plaintext Passwords
Plaintext passwords are the most dangerous type of credential leak because they require no additional processing. Attackers can directly attempt logins across email providers, banking platforms, and any other service where a JobTH user may have reused their password. With over 1.2 million email-password pairs availble, this dataset is a ready-made toolkit for large-scale credential stuffing campaigns targeting platforms across Thailand and internationally.
What Was Exposed in the JobTH Breach
- Email Address
- Plaintext Password
Why Plaintext Password Storage Is Particularly Dangerous
Storing passwords in plaintext is a fundamental security failure that violates basic industry standards. Every legitimate platform should hash passwords using a strong algorithm such as bcrypt, Argon2, or scrypt before storing them. When a database storing plaintext passwords is breached, there is no defense layer between the attacker and full account access. For the 1.2 million users affected by the JobTH breach, any account where they reused their password is now at immediate risk of takeover.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a backend data store and exports user records. This can happen through SQL injection attacks, exploitation of unpatched software vulnerabilities, or compromised administrative credentials. The attacker typically packages the exported data and sells it on dark web marketplaces or shares it in closed forums. In JobTH's case, the fact that plaintext passwords were stored means the breach had maximum impact with minimal post-processing required by the attacker.
Check If Your Data Was Exposed
HEROIC's DarkWatch continuously monitors over 400 billion exposed records, including breaches like JobTH, to alert you when your email or passwords appear in newly surfaced data dumps. Search your email address at HEROIC now to find out if your credentials were part of this breach.
Breach Breakdown
1,227,433 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds