Your Password May Already Be Circulating. The Kings Breach Exposed 74K Records.
HEROIC analysts found the Kings breach in August 2018 while scanning dark web forums for newly circulating credential databases. Kings was a US-based sports information website that has since gone offline, but its user database did not disappear with it. The breach exposed 74,359 records containing email addresses and passwords stored in plain text with no encryption applied. For a site with no financial transactions or particularly sensitive content, the failure to protect even basic login credentials meant that every registered user was left vulnerable to account takeover on other platforms where they reused those same credentials.
How Leaked Email and Password Pairs Enable Immediate Account Takeover
Plain text passwords are the most dangerous kind of leaked credential because no additional work is required to use them. When a criminal gets a database containing email addresses paired with readable passwords, they can immediately begin testing those combinations against other websites. The process is largely automated, meaning thousands of sites can be tested in a short time frame. Sports fans who registered on Kings often used the same email and password for ESPN, sports betting platforms, merchandise stores, and social media accounts. A seperate account on any one of those platforms could be taken over the moment an attacker tries the Kings credentials against it.
What Was Exposed in the Kings Breach
- Email Address
- Plaintext Password
Your Accounts Could Still Be at Risk From the Kings Breach Years Later
Old breach data does not become harmless over time. Databases from 2018 are still bought and sold on criminal forums, and credential stuffing attacks using older data continue to succeed because many people never change passwords after a breach they are not even aware of. If a Kings user never recieved a notification about the breach, they may still be using the same password on other sites today. That means the risk of identity theft, unauthorized account access, and financial fraud from this 2018 breach remains very real in the present day.
How Database Breaches Work
A database breach occurs when an attacker exploits a security weakness in a website's infrastructure, such as outdated software, an SQL injection vulnerability, or an improperly secured server. Once the attacker has access, they copy the user database. If that database stores passwords in plain text rather than as scrambled hashes, every user's password is readable and ready to use immediately. The stolen data is then sold or shared on criminal networks, often resurfacing multiple times over the following years in new collections and data dumps.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email address against a database of over 400 billion stolen records, including those from the Kings breach. You will find out instantly whether your information has been compromised and get clear guidance on what to do next. Run your free scan at HEROIC today and take control of your personal security.
Breach Breakdown
74,359 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds