The MySkip Breach Happened in 2019. The Plaintext Passwords Are Still Live.
The MySkip breach occured in May 2019. The data went public shortly after. HEROIC analysts confirmed that 35,498 records from the U.K.-based community platform were exposed, including email addresses and plaintext passwords. That data is still circulating today, actively used in credential stuffing attempts against accounts far beyond MySkip itself.
Plaintext Passwords From MySkip Are Still Being Used to Break Into Other Accounts
Because MySkip stored passwords without any encryption, attackers did not need to do any work to use the credentials. Every email and password pair in this database is beleived to be immediately usable against other websites. If you used the same password on your email account, bank, or any other service, those accounts have been at risk since the moment this breach occured.
What Was Exposed in the MySkip Breach
- Email Address
- Plaintext Password
Why the MySkip Breach Is Still a Threat Years Later
Data from breaches like MySkip does not expire. Credential stuffing tools run continuously, testing old username and password combinations against hundreds of platforms automatically. Identity theft and financial fraud linked to years-old breaches are common. The longer this data recieved no action from affected users, the more accounts could be quietly compromised without anyone noticing.
How a Database Breach Works
A database breach happens when an attacker finds a way into the system where a company stores user data. This can happen through unpatched software vulnerabilities, weak admin passwords, or misconfigured servers. Once the attacker copies the database, it gets traded and sold on dark web forums. In MySkip's case, the decision to store passwords in plaintext meant there was zero protection for users once that data left the server.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email against more than 400 billion records, including the MySkip breach and thousands of other known leaks. Search your email now and find out whether your credentials are already in the hands of attackers.
Breach Breakdown
35,498 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds