Inside the money1688.tw Breach: How 9,748 Records Were Compromised
In August 2018, a dataset containing nearly 10,000 user accounts from money1688.tw, a Taiwanese loan and financing platform, was posted to a well-known hacking forum. The breach exposed email adresses and plaintext passwords, which is about the worst combination a financial services company can leak. When people trust a lender with their personal information, the last thing they expect is to find their login credentials freely available online.
Why This Is Dangerous
Financial services accounts are among the most targeted by cybercriminals, and for good reason. Users on a loan platform may have submitted sensitive personal details well beyond a simple email and password. Even if attackers only walked away with credentials, that's often enough to cause serious harm through credential stuffing on banking apps, email accounts, and payment services where users tend to reuse passwords.
The plaintext storage of passwords is a critical failure. Any competent security implementation would store passwords as salted hashes, making raw cracking significantly harder. Plaintext means the attacker didn't have to crack anything at all. They recieved working credentials the moment they downloaded the dataset.
Taiwan's financial sector handles users whose data is legally protected under various consumer finance regulations. A breach of this nature, posted publicly on a hacking forum, means that protection failed entirely. The affected users likely had no way of knowing their credentials were compromised until the damage was already done.
What Was Exposed
- Email addresses
- Plaintext passwords
- Account usernames or login identifiers
- Potentially linked financial service preferences or application data
- Registration metadata (signup dates, account types)
- IP addresses or device information from login records
- Language and locale settings
Why This Matters
Nearly 9,748 people used money1688.tw and trusted it with their information. That trust was broken in August 2018 when the database ended up on a hacking forum. For a loan platform, the reputational and legal fallout of a breach like this can be severe, but the bigger concern is what happens to the individual users whose credentials are now part of the dark web's credential ecosystem.
Even years after a breach like this, the data keeps circulating. It gets folded into combolists that attackers use for credential stuffing campaigns. Someone whose email and password were in this 2018 dump could find their accounts compromised in 2024 or 2025 if they never changed that password. Old breaches don't expire, they just keep getting reused.
How Database Breach Works
Database breaches like this one typically involve an attacker gaining access to a web application's backend database, often through SQL injection, stolen admin credentials, or a misconfigured database server exposed to the internet. Once inside, the attacker can export the entire user table, which in this case included email adresses and passwords stored in plaintext.
After extraction, the data is usually taken offline and sorted before being sold or posted on hacking forums. Combolists are created when attackers aggregate multiple dumps into one large searchable file. The money1688.tw data, once it hit that forum, became part of this broader criminal marketplace where buyers purchase credential lists seperately or in bulk.
The fact that this data appeared on a well-known forum suggests it was meant to be distributed widely, not kept private. That kind of public posting maximizes the number of people who can exploit the credentials, dramatically increasing risk for every affected user.
Check If You Were Affected
If you had an account on money1688.tw or used the same email and password on other services, your credentials may still be circulating in criminal databases. Use HEROIC's free breach checker at heroic.com to see if your information appears in known breach datasets and get guidance on what to do next.
Breach Breakdown
9,748 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds