My Admission
We noticed a significant data leak surfacing on a well-known hacking forum on August 26, 2018. This incident involved a now-defunct Nigerian educational platform, My Admission, and exposed a considerable number of user credentials. What struck us immediately was the inclusion of plaintext passwords alongside email addresses, a critical vulnerability that significantly amplifies the risk of further compromise for affected individuals and potentially their associated accounts. The sheer volume of records, while not exceptionally high in the grand scheme of enterprise breaches, represents a concentrated pool of potentially exploitable credentials.
The breach breakdown reveals a database compromise affecting 11,830 users of My Admission. The leaked data, published in a single dataset, consists of two primary fields: Email Address and Plaintext Password. This indicates a direct exfiltration of user authentication data, likely from a user account database. The absence of more complex data types suggests the threat actor's primary objective was credential harvesting, potentially for use in credential stuffing attacks against other platforms or for direct account takeover. The source structure of the leak points to a direct database dump or a similarly unsophisticated extraction method, highlighting a lack of robust database security at the time of the incident. The leak location on a prominent hacking forum ensures wide dissemination among malicious actors.
While this specific breach did not generate widespread mainstream news coverage at the time, it aligns with a broader trend of educational platforms being targeted for their user data, often due to perceived lax security and the high value of student credentials. Research from various cybersecurity firms has consistently highlighted the vulnerability of academic institutions and related services to credential harvesting and subsequent attacks. The nature of this leak, specifically the plaintext passwords, is a recurring theme in credential stuffing campaigns that exploit password reuse across different online services. OSINT investigations into similar historical breaches often reveal a pattern of attackers targeting less secure regional platforms as a stepping stone to more valuable targets.
Breach Breakdown
11,830 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds