LasVegas World of Mouth
We're seeing a concerning resurgence of older breaches, often resurfacing in aggregated combolists and fueling credential stuffing attacks. We encountered this particular breach during a sweep of a known credential marketplace, where a database dump from **LasVegas World of Mouth**, a defunct online social gaming platform, was being offered for sale. What struck us wasn't the size of the breach – just over **74,000** records – but the age of the data and the fact that passwords were stored in plaintext. This combination significantly increases the risk for individuals whose data was compromised, even years after the initial breach.
LasVegas World of Mouth: Plaintext Passwords Fuel Resurgent Credential Stuffing
In July of **2018**, **LasVegas World of Mouth**, a U.S.-based affiliate-driven online social gaming and chat platform, suffered a data breach that has now resurfaced. The breach was discovered this week on a well-known hacking forum where the database was being advertised. The fact that passwords were stored in plaintext immediately raised a red flag. While not a massive breach in terms of record count, the nature of the exposed data, coupled with its reappearance after several years, makes it relevant to enterprises today.
The risk stems from the likelihood that many individuals reused their **LasVegas World of Mouth** passwords on other, more critical accounts. The age of the breach also creates a false sense of security; users may assume the risk has passed. The combination of plaintext storage and password reuse amplifies the potential for successful credential stuffing attacks against a wide range of online services.
- Total records exposed: 74,363
- Types of data included: Email addresses, plaintext passwords
- Sensitive content types: Credentials
- Source structure: Database dump
- Leak location(s): Prominent hacking forum
- Date of first appearance: July 22, 2018 (original breach), [Current Date] (reappearance on forum)
The practice of storing passwords in plaintext is a well-documented security failing. As Troy Hunt, creator of Have I Been Pwned, has repeatedly emphasized, any organization storing passwords without proper hashing and salting is exposing its users to significant risk. The reappearance of this data highlights the long-term consequences of such poor security practices.
While we haven't seen widespread discussion of this specific resurfaced breach in major news outlets, similar incidents involving older data sets are regularly reported. For example, BleepingComputer recently covered a large-scale credential stuffing campaign leveraging older leaks. This highlights the ongoing threat posed by legacy breaches and the importance of proactive credential monitoring.
Breach Breakdown
74,363 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds