The LovePlanet Breach Left 4.7 Million Passwords in Plain Text
HEROIC analysts identified 4,705,425 exposed accounts tied to LovePlanet, a Russian dating site breach dated January 2015. The exposed data includes email addresses, usernames, and passwords stored in plaintext, meaning there was no encryption at all standing between an attacker and a user's actual password.
Why Plaintext Passwords Are the Worst Case Scenario
Most breaches involve hashed passwords, which at least require attackers to crack or guess the original password before using it. In the LovePlanet breach, passwords were stored in plaintext, meaning anyone who obtained the database could read every password directly, with no cracking required. Combined with matching email addresses and usernames, this is about as complete a set of login credentials as an attacker could ask for.
What Was Exposed in the LovePlanet Breach
- Email addresses
- Usernames
- Plaintext passwords
Why This Matters for LovePlanet Users
On a dating site, users often reuse the same password they use for email or social media, never expecting that password to be visible to anyone else. Because these passwords were never hashed, attackers can use them immediately, with no cracking delay involved, to attempt logins on other accounts through credential stuffing. Anyone who reused a LovePlanet password anywhere else should treat that other account as at risk right now.
How This Database Breach Exposed Plaintext Data
This incident is classified as a database breach, meaning attackers gained direct access to LovePlanet's user database rather than collecting data through malware. What makes this case worse than a typical database breach is that the site stored passwords in plaintext instead of using a hashing algorithm to scramble them. That means once attackers accessed the database, they had immediate, ready-to-use passwords for every one of the 4,705,425 accounts, with no additional cracking step required.
Check If You Are Affected by the LovePlanet Breach
You don't need to guess whether your information was part of the LovePlanet breach or any other leak. HEROIC's free breach scanner checks your email address against a database of more than 400 billion leaked records and shows you exactly what was exposed. If you find a match, change the password on any account still using it and enable multi-factor authentication where you can.
Breach Breakdown
4,705,425 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds