Koaci
We noticed a significant leak surfacing on a well-known hacking forum on July 23rd, 2018. This particular dataset, attributed to the online news portal Koaci, involved a relatively modest number of user accounts, specifically 14,593. What struck us was the straightforward nature of the compromised information: standard email addresses paired with MD5 password hashes. While not the most sophisticated attack vector, the presence of such credentials, even if hashed, warrants immediate attention due to their potential for reuse across other platforms and the inherent risks associated with weak hashing algorithms.
The breach originated from a database compromise at Koaci, an outlet focusing on West African political, economic, and social news. The leaked data, comprising 14,593 email addresses and their corresponding MD5 password hashes, was disseminated on a prominent cybercrime marketplace. The significance of this leak lies in the potential for credential stuffing attacks. While MD5 is a deprecated hashing algorithm, it remains vulnerable to brute-force and rainbow table attacks, especially for common or weak passwords. The exposure of these email-password pairs, even if hashed, can be leveraged by threat actors to gain unauthorized access to other services where users may have reused their credentials, thereby expanding the attack surface beyond Koaci itself. This incident underscores the persistent threat of database breaches and the ongoing exploitation of legacy security practices.
At the time of the leak in July 2018, there was no widespread public reporting or significant news coverage specifically detailing the Koaci breach. However, the general landscape of data breaches in 2018 was characterized by a continuous stream of exposed credentials from various online services. Research from cybersecurity firms throughout that year consistently highlighted the prevalence of database compromises and the subsequent sale of user data on dark web forums. The method of compromise, a database leak, aligns with common attack vectors observed during that period, where vulnerabilities in web applications or direct database access allowed threat actors to exfiltrate sensitive user information.
---
Our analysis flagged a substantial data exposure event discovered on July 23rd, 2018, originating from a source identified as Koaci. This breach impacted a notable segment of user accounts, totaling 14,593 individuals. The exposed data consisted of email addresses and password hashes, specifically in the MD5 format. The sheer volume, coupled with the readily exploitable nature of MD5 hashes, makes this a critical incident requiring thorough investigation and remediation to prevent downstream impacts.
Breach Breakdown: Koaci Incident
The Koaci breach, a West Africa-focused online news portal, was identified through a dataset leaked on a prominent hacking forum. The compromised database yielded 14,593 records, each containing an email address and an MD5 password hash. This type of breach, classified as a database compromise, is particularly concerning because MD5, despite its age and known cryptographic weaknesses, is still frequently used. Threat actors can efficiently crack these hashes using readily available tools and pre-computed rainbow tables, especially if users employed simple or common passwords. The potential for this data to be used in combolist attacks, targeting other services where users might have reused their credentials, is a significant risk factor.
While the Koaci breach itself did not generate extensive mainstream media attention at the time of its discovery in July 2018, it fits within a broader pattern of credential data leaks prevalent in the cybersecurity landscape. Online OSINT investigations and reports from security researchers during that period frequently documented the illicit trade of user credentials on dark web marketplaces. The use of MD5 hashes, though increasingly discouraged, remained a common feature in many such leaks, underscoring the ongoing challenges in enforcing robust password security practices across diverse online platforms.
Breach Breakdown
14,593 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds