Mebo TCM
We observed a data leak originating from a dataset posted on a prominent hacking forum on August 26, 2018. The dataset, attributed to Mebo TCM, a now-defunct Chinese medical information website focused on acupuncture studies, exposed the credentials of 3,648 registered users. What struck us as particularly noteworthy, beyond the typical credential exposure, is the age of the compromised data and the specific domain of the affected entity, suggesting potential long-tail risks from legacy systems or archived user bases.
The breach breakdown reveals a straightforward database compromise, resulting in the exfiltration of 3,648 user records. The exposed data primarily consists of email addresses and their corresponding MD5 password hashes. The source structure points to a direct database dump. While the number of records is relatively small, the use of MD5 hashing, a cryptographically weak algorithm, means that these password hashes are highly susceptible to brute-force attacks and rainbow table lookups, effectively rendering them as plain text for attackers with sufficient resources. This type of credential data is frequently repurposed for credential stuffing attacks against other platforms where users may have reused their passwords.
At the time of the leak, Mebo TCM was a niche platform for acupuncture research. There was no significant public news coverage surrounding this specific incident, and OSINT analysis does not reveal any immediate connections to broader campaigns or known threat actor groups. However, the presence of such older, weakly hashed credentials in public forums underscores the persistent threat posed by forgotten or neglected databases, which can serve as fertile ground for attackers looking to exploit outdated security practices.
Breach Breakdown
3,648 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds