LokalHoszt Breach: 44,406 Hungarian Hosting User Passwords Leaked
In August 2018, LokalHoszt, a now-defunct Hungarian local web hosting platform, suffered a data breach that exposed the account information of 44,406 users. The breach involved both a direct database compromise and subsequent combolist distribution, with email addresses and plaintext passwords circulating in underground forums. As a web hosting provider, LokalHoszt held accounts for individuals and small businesses who trusted the platform with their online infrastructure -- making the exposure of plaintext passwords a serious failure with lasting consequences for affected users.
Why This Is Dangerous
Plaintext password storage eliminates any barrier between an attacker and immediate account access. Unlike hashed passwords, which require significant computational effort to reverse, plaintext credentials are ready to use the moment they are exfiltrated. The 44,406 email and password pairs from the LokalHoszt breach can be tested against banking portals, email services, other hosting providers, and business software platforms using automated credential stuffing tools. Hosting customers often use the same password across their hosting account, domain registrar, business email, and content management systems -- meaning that a single breach at a hosting provider can cascade into compromised websites, hijacked domains, and business email account takeovers. Users who have not changed the password they used for LokalHoszt remain at risk across every platform where they reused that credential.
What Was Exposed
- Email addresses for 44,406 LokalHoszt user accounts
- Plaintext (unencrypted) passwords stored without hashing or salting
- Account data associated with the LokalHoszt Hungarian hosting platform
- Credentials compiled into combolists and distributed across underground forums
Why This Matters
Web hosting customers are a high-value target for credential attackers because a hosting account provides access to website files, databases, and email systems. The LokalHoszt breach exposed credentials in plaintext, meaning they were immediately actionable for any attacker who obtained the dataset. Credentials from this breach have been circulating in combolist repositories since 2018 and continue to appear in active credential stuffing datasets. Many affected users almost certainly recieve no warning from the now-defunct company, leaving them exposed indefinitely unless they discovered the breach through an external notification service. The geographic specificity of Hungarian hosting customers also makes the data valuable for targeted regional attacks, as many of thier accounts may include access to Hungarian business websites and email infrastructure.
How Database and Combolist Breaches Work
A database breach typically occured when an attacker exploited a vulnerability in the target's web infrastructure -- such as an SQL injection flaw, a server misconfiguration, or compromised administrative credentials. Once inside the hosting provider's systems, the attacker extracted the user database containing email addresses and plaintext password fields. Because no hashing or encryption protected the passwords, no further processing was required before the data could be weaponized. The extracted records were formatted into a combolist, a structured file used by automated tools to run login attempts across hundreds of websites simultaneously. Combolists from hosting provider breaches are particulary prized because they often yield working credentials for website control panels, domain management interfaces, and business email services.
Check If You Are Affected
If you ever registered an account with LokalHoszt at lokalhoszt.hu, your email address and password may be part of this breach. Take immediate action to protect yourself:
- Search your email address in HEROIC's breach database to confirm whether your LokalHoszt credentials were exposed
- Change the password you used for LokalHoszt on every other platform where you have used the same password
- Enable two-factor authentication on your email account and any hosting, domain, or business software accounts you use
- Review your websites and hosting accounts for unauthorized changes, new files, or unexpected redirects
- Use a password manager to generate and maintain unique passwords for each account you hold
- Be alert to phishing emails targeting Hungarian hosting customers or website operators
HEROIC monitors breach data continuously and can alert you in real time when your credentials appear in newly discovered datasets. Proactive breach monitoring gives you the fastest possible response time, reducing the window of opportunity for attackers to exploit your exposed data.
Breach Breakdown
44,406 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds