Lost Tribe of Everton Breach: 55K Liverpool Heritage Site Users Leaked
HEROIC's DarkHive intelligence system discovered the Lost Tribe of Everton and Scottie Road data breach, exposing 55,952 records. The breach occured in August 2018 and targeted this UK community website dedicated to preserving the heritage and memories of Liverpool neighborhoods. Attackers obtained email addresses and plaintext passwords from the site, leaving every affected user immediately vulnerable without any cracking required.
Why This Is Dangerous
Plaintext passwords mean attackers can log into other online services on behalf of victims the moment they access the database. Community heritage sites attract users who tend to be long-term members with stable email addresses, meaning thier credentials are likely still active on many platforms. Attackers specifically seek out breaches from community sites because these users often reuse the same email and password combination across banking, social media, and shopping accounts. Credential stuffing tools can test 55,000 credential pairs against hundreds of websites in a matter of hours, turning this breach into a weapon for widespread account takeover.
What Was Exposed
- Email Address
- Plaintext Password
Why This Matters
Breaches from community and heritage sites are easy to overlook because these organizations lack the public profile of major brands. However, the stolen credentials circulate in the same combolists as data from larger breaches, and attackers apply them in the same automated attacks. UK residents affected by this breach face risks including account takeover of bank and shopping accounts, identity theft, and phishing attacks that use the exposed email address to craft convincing deception campaigns. Organizations with employees who are members of community websites should be aware that personal credential reuse can create enterprise security vulnerabilities.
How Database and Combolist Breaches Work
Database breaches occur when attackers identify and exploit weaknesses in web hosting environments, including unpatched CMS software, default credentials on admin panels, or SQL injection vulnerabilities in forum software. Once access is gained, the attacker extracts user records and compiles them into combolists. The failure to hash passwords in the Lost Tribe of Everton and Scottie Road case was a seperate and critical security lapse that amplified the damage. These combolists are then distributed and sold across underground markets, where they recieve ongoing use for years as attackers continue testing the credentials across different platforms.
Check If You Are Affected
HEROIC offers a free identity scanner that searches over 400 billion records, including data from breaches like Lost Tribe of Everton and Scottie Road. Visit heroic.com to scan your email address and find out if your information was exposed. If you were a member of this site in 2018 or earlier, consider changing your password on all accounts that use the same credentials.
Breach Breakdown
55,952 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds