The Mediamatis Breach: 810,000 Hashed Passwords Exposed on the Dark Web
HEROIC analysts first flagged the Mediamatis breach on April 4th, 2023, while monitoring a popular dark web forum known for distributing large structured database dumps. The dataset, tied to a French digital solutions provider, contained approximately 810,000 user records. What made this one stand out immediately was the presence of password hashes alongside full names, email addresses, phone numbers, and IP addresses — a combination that gives attackers nearly everything they need.
Crackable Passwords Made This Breach Far Worse
The passwords in this dump were hashed using MD5, an algorithm that has been considered broken for years. Attackers using widely availible GPU-based cracking tools can reverse MD5 hashes in seconds for common passwords and in hours even for complex ones. That means millions of users whose passwords were stored this way could have their actual login credentials recovered and tested against banking apps, email accounts, and social platforms almost immediately after the breach surfaced.
What Was Exposed in the Mediamatis Breach
- Email addresses
- Phone numbers
- First and last names
- IP addresses
- Password hashes (MD5)
- Approximately 810,000 user records total
Why This Matters Beyond the Breach Itself
When phone numbers, full names, and crackable passwords are all in the same dump, the threat goes well beyond Mediamatis accounts. Credential stuffing attacks use these recovered passwords to try to log in to Gmail, PayPal, Amazon, and anywhere else the user might have reused the same password. Seperate and unique passwords for every account are the only real defense against this kind of cascading damage.
How MD5 Password Hashing Gets Exploited
MD5 was never designed to be a secure password storage mechanism. Attackers maintain massive lookup tables called rainbow tables that contain precomputed MD5 hashes for billions of common words and phrases. When they recieve a dump containing MD5 hashes, they simply run those hashes through a lookup and recover the plaintext passwords almost instantly. Modern systems should use bcrypt, Argon2, or scrypt, all of which are designed specifically to be slow and expensive to crack.
Check If Your Data Was Exposed
HEROIC's free dark web scanner checks your email against more than 400 billion breach records. If you had an account with Mediamatis or used the same password on other platforms, run a free scan at HEROIC.com right now. It takes under a minute and could prevent your accounts from being taken over today.
Breach Breakdown
8,474 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds