MatchFlick
We noticed a recently surfaced dataset originating from a breach affecting MatchFlick, a U.S.-based film information and review platform that ceased operations sometime prior to the leak. The dataset, disseminated on a prominent hacking forum on August 26, 2018, comprises 9,452 user records. What struck us as particularly relevant is the inclusion of both email addresses and MD5 password hashes, a combination that significantly lowers the barrier for credential stuffing attacks against other services.
The MatchFlick breach, discovered through routine monitoring of underground forums, exposed the credentials of 9,452 registered users. The compromised data primarily consists of email addresses and their corresponding MD5 password hashes. While MD5 is a deprecated hashing algorithm, its widespread use in older systems and its susceptibility to brute-force attacks mean these hashes remain a valuable commodity for threat actors. The source structure appears to be a direct database dump, indicating a potentially straightforward exfiltration method. The leak location was a well-established hacking marketplace, suggesting a deliberate effort to monetize the compromised information.
While the MatchFlick platform itself is no longer operational, the implications of this leak extend to its former user base. The presence of these credentials on public forums increases the likelihood of them being incorporated into larger combolists. These lists are then systematically tested against various online services, exploiting password reuse – a pervasive issue in user security practices. The age of the leak (August 2018) does not diminish its potential impact, as many users may not have updated their credentials since the platform's active period.
Breach Breakdown
9,452 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds