Stock Photo Site microStock Leaks 151,953 Contributor Records
HEROIC Cybersecurity analysts identified 151,953 user records exposed in a breach of microStock, a Russian stock photography, illustration, and video marketplace operating at microstock.ru. The leak surfaced on February 1, 2025 and included email addresses, usernames, IP addresses, birthdays, and password hashes stored as salted MD5.
Why This Stock Media Breach Is Dangerous
A stock media platform sits at the intersection of creative work and commerce. Contributor accounts hold payout settings, tax documents, and portfolios of licensed assets. The exposed database gives attackers not just the credentials to take over those accounts but also birthdays and IP addresses that sharpen any follow-on social engineering against creators.
What Was Exposed in microStock
- 151,953 user records from microstock.ru
- Email addresses
- Usernames
- IP addresses
- Birthdays
- Password hashes stored as MD5 with per-user salts
Why This Matters
Salted MD5 is stronger than plain MD5, but it still falls quickly to modern GPU cracking rigs. Any recovered password will feed credential stuffing against the contributor's email, banking, and cloud storage accounts. For artists and photographers, a compromised microStock account can be used to redirect payouts, hijack portfolios, or ship stolen premium assets to other sites. The exposed birthday and email combination also fuels identity theft and targeted phishing tailored to the creative marketplace.
How Database Breaches Hit Creative Marketplaces
Marketplaces built on older PHP stacks often rely on hashing choices made a decade ago, with MD5 and simple salts left in place for backwards compatibility. SQL injection, exposed backups, or compromised admin credentials give attackers a path to the user table. Once the data is out, buyers on dark web forums crack the hashes, pair them with the stored emails and birthdays, and resell the set for phishing, fraud, and account takeover campaigns.
Check If You Are Affected
HEROIC's DarkHive scanner indexes more than 400 billion exposed records, including the microStock dataset. Search your email to see if your contributor account was included, rotate any password reused from microStock, and enable multi-factor authentication on your email and financial accounts.
Breach Breakdown
151,953 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds