Researchers Link Kristalliks.co.uk to 235,000 Plaintext Passwords
HEROIC researchers identified the Kristalliks.co.uk breach after the dataset surfaced on a dark web forum in August 2018. The breach exposed 235,356 records from this now-defunct UK platform, and what made it accessable to attackers in the worst possible way was the storage method: passwords were saved in plain text, with no encryption or hashing whatsoever. That means anyone who got hold of this database had immediate, direct access to every user's real password without any need to crack it.
Why Plaintext Passwords Make This Breach Especially Dangerous
Most companies at least attempt to obscure passwords using hashing. Kristalliks.co.uk did not. Every password in this database was stored exactly as users typed it. Attackers who obtained this data could log into victims' accounts on other services instantly, using those exact passwords. Credential stuffing tools can test thousands of email and password combinations per minute across banking sites, email providers, and social platforms, making recieved plaintext passwords one of the most exploitable breach types out there.
What Was Exposed in the Kristalliks.co.uk Breach
- Email Address
- Plaintext Password
Why UK Users Face Ongoing Risk From This Breach
Even though Kristalliks.co.uk no longer operates, the data does not disappear with the website. The 235,356 records from this breach have been bundled into larger credential lists and traded repeatedly on dark web markets since 2018. If any user on this platform reused their password on a banking app, a shopping site, or their work email, those accounts have been at risk for years. Credential stuffing, account takeover, and identity theft are all direct outcomes of plaintext password exposure at this scale.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized entry to a company's server and copies the underlying user data. When a platform shuts down, it does not automatically delete or secure its servers. Defunct platforms like Kristalliks.co.uk are often targeted precisely because they are less likely to have active security monitoring after closure. Attackers export the database, then post or sell it in dark web communities that specialize in trading stolen credentials.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email against over 400 billion leaked records, including breaches like Kristalliks.co.uk, to tell you instantly what was exposed. If you ever had an account on this platform or used the same password elsewhere, run a free scan now to see exactly what attackers may already have on you.
Breach Breakdown
235,356 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds