Researchers Link the Multimedia.de Breach to 25,667 Stolen Credentials From a German Portal
HEROIC analysts identified a data breach connected to Multimedia.de, a German online portal that once served job seekers, business directory users, and multimedia industry professionals before ceasing operations. The breach occured in March 2018, and the compromised data was later posted on a prominent hacking forum where HEROIC's dark web monitoring team captured it. The exposed dataset contained 25,667 records, each consisting of an email address and a plaintext password stored without any encryption. For users of a platform serving the employment and education sectors in Germany, the exposure of readable credentials created immediate and long-lasting risks for account security across any service where those same passwords were reused.
Why the Multimedia.de Breach Is a Serious Credential Threat
Plaintext password storage is one of the most preventable failures in data security, and when it leads to a public forum post exposing 25,667 accounts, the consequences are far-reaching. Anyone who downloaded the Multimedia.de data from the hacking forum received a ready-to-use list of email and password pairs that required no further processing. For a platform catering to professionals in the multimedia industry, these email addresses likely belonged to people with active professional accounts on LinkedIn, Xing, industry tools, and corporate email systems. That kind of audience makes the data more valuable to attackers looking for corporate footholds, not just individual account takeovers. The recieved list was immediately actionable for credential stuffing campaigns.
What Was Exposed in the Multimedia.de Breach
- Email Addresses
- Plaintext Passwords
Why This Matters for German Users and Beyond
Job and career portals collect sensitive personal information and are used by people who trust them with professional identities. When that trust is violated and the data surfaces on underground forums, it opens the door to credential stuffing, account takeover, and identity theft at scale. For the 25,667 individuals in the Multimedia.de dataset, the danger is not limited to the portal itself, which no longer operates. It extends to every other service those users registered with the same email and password combination. That includes personal email, banking apps, corporate systems, and social media. The fact that this data is several years old does not reduce the risk: stealer logs and combolists are routinely recirculated and incorporated into newer attack campaigns. Financial fraud and business email compromise are among the most seriouse downstream consequences when professional credentials are exposed.
How Database Breaches and Combolists Work
The Multimedia.de incident is classified as both a database breach and a combolist event. A database breach occurs when an attacker exploits a vulnerability in a web application or server to extract stored user data. In this case, the attacker gained access to the user database and exported records that the platform had stored with passwords in plaintext rather than using secure hashing algorithms. That exported data is then formatted as a combolist: a clean, structured file of email-password pairs that automated tools can process at high speed. Combolists are a staple of credential stuffing operations, where attackers test stolen pairs against many different websites simultaneously. Once posted to a hacking forum, the Multimedia.de data became available to any number of criminal actors, and the list has almost certainly been merged into larger aggregated credential databases that continue to circulate today.
Check If You Are Affected
If you had an account on Multimedia.de or beleive you may be in a German data breach or combolist, run a free scan at heroic.com. HEROIC's breach scanner searches a database of over 400 billion exposed records to check whether your email address has appeared in known breaches. The scan is seperate from any account creation and takes only seconds. If you are confirmed as affected, change the compromised password immediately on any service where it was reused and enable two-factor authentication wherever it is available.
Breach Breakdown
25,667 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds