Breach Intelligence Report 29 Dec 2025

Koaci

HEROIC
HEROIC Threat Intelligence Team
Email Address Password Hash
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 14,593
Source Type Database,Combolist
Origin Darkweb
Password Type MD5

We noticed a significant leak surfacing on a well-known hacking forum on July 23rd, 2018. This particular dataset, attributed to the online news portal Koaci, involved a relatively modest number of user accounts, specifically 14,593. What struck us was the straightforward nature of the compromised information: standard email addresses paired with MD5 password hashes. While not the most sophisticated attack vector, the presence of such credentials, even if hashed, warrants immediate attention due to their potential for reuse across other platforms and the inherent risks associated with weak hashing algorithms.

The breach originated from a database compromise at Koaci, an outlet focusing on West African political, economic, and social news. The leaked data, comprising 14,593 email addresses and their corresponding MD5 password hashes, was disseminated on a prominent cybercrime marketplace. The significance of this leak lies in the potential for credential stuffing attacks. While MD5 is a deprecated hashing algorithm, it remains vulnerable to brute-force and rainbow table attacks, especially for common or weak passwords. The exposure of these email-password pairs, even if hashed, can be leveraged by threat actors to gain unauthorized access to other services where users may have reused their credentials, thereby expanding the attack surface beyond Koaci itself. This incident underscores the persistent threat of database breaches and the ongoing exploitation of legacy security practices.

At the time of the leak in July 2018, there was no widespread public reporting or significant news coverage specifically detailing the Koaci breach. However, the general landscape of data breaches in 2018 was characterized by a continuous stream of exposed credentials from various online services. Research from cybersecurity firms throughout that year consistently highlighted the prevalence of database compromises and the subsequent sale of user data on dark web forums. The method of compromise, a database leak, aligns with common attack vectors observed during that period, where vulnerabilities in web applications or direct database access allowed threat actors to exfiltrate sensitive user information.

---

Our analysis flagged a substantial data exposure event discovered on July 23rd, 2018, originating from a source identified as Koaci. This breach impacted a notable segment of user accounts, totaling 14,593 individuals. The exposed data consisted of email addresses and password hashes, specifically in the MD5 format. The sheer volume, coupled with the readily exploitable nature of MD5 hashes, makes this a critical incident requiring thorough investigation and remediation to prevent downstream impacts.

Breach Breakdown: Koaci Incident

The Koaci breach, a West Africa-focused online news portal, was identified through a dataset leaked on a prominent hacking forum. The compromised database yielded 14,593 records, each containing an email address and an MD5 password hash. This type of breach, classified as a database compromise, is particularly concerning because MD5, despite its age and known cryptographic weaknesses, is still frequently used. Threat actors can efficiently crack these hashes using readily available tools and pre-computed rainbow tables, especially if users employed simple or common passwords. The potential for this data to be used in combolist attacks, targeting other services where users might have reused their credentials, is a significant risk factor.

While the Koaci breach itself did not generate extensive mainstream media attention at the time of its discovery in July 2018, it fits within a broader pattern of credential data leaks prevalent in the cybersecurity landscape. Online OSINT investigations and reports from security researchers during that period frequently documented the illicit trade of user credentials on dark web marketplaces. The use of MD5 hashes, though increasingly discouraged, remained a common feature in many such leaks, underscoring the ongoing challenges in enforcing robust password security practices across diverse online platforms.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Password Hash
Password Types MD5
Date Leaked 29 Dec 2025
Check in 5 seconds

14,593 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,532 scanned today
Breach Rank #11,070 by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $105.6K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance