Journal of Corrosion Science and Engineering
We noticed a significant data leak surfacing on a prominent hacking forum on August 26, 2018. The compromised dataset originated from the Journal of Corrosion Science and Engineering, a U.K.-based academic publication. What struck us was the inclusion of plaintext passwords alongside email addresses, a configuration that immediately elevates the risk profile for affected individuals. This breach, impacting 11,084 users, represents a clear vulnerability in how sensitive user credentials were handled by the journal's infrastructure.
The breach breakdown reveals a database compromise, with the leaked data subsequently appearing as a combolist on a public hacking forum. The dataset, totaling 11,084 records, primarily contains email addresses and, critically, plaintext passwords. This direct exposure of credentials, rather than hashed or salted equivalents, bypasses common credential stuffing defenses and allows for immediate unauthorized access to other services where users may have reused these credentials. The source structure suggests a direct dump from a user account database, with no apparent obfuscation or encryption applied to the password field.
At the time of the leak, there was no widespread media coverage specifically detailing this incident. However, the nature of the exposed data – particularly plaintext passwords – aligns with a recurring threat theme of credential harvesting and subsequent exploitation across multiple platforms. Researchers have consistently warned about the dangers of plaintext password storage, as evidenced by numerous past breaches where such vulnerabilities have led to cascading account takeovers.
Breach Breakdown
11,084 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds