Breach Intelligence Report 14 Oct 2025

Nansei Feather

HEROIC
HEROIC Threat Intelligence Team
Email Address Plaintext Password
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 9,821
Source Type Database,Combolist
Origin Darkweb
Password Type Plaintext

We noticed a recent resurgence of interest surrounding a dataset attributed to Nansei Feather, a Taiwan-based bedding manufacturer. This breach, initially documented in August 2018, has resurfaced on public forums, prompting a review of its contents and potential ongoing impact. What struck us was the continued accessibility of this relatively old data, particularly the inclusion of plaintext passwords, which significantly amplifies the risk of credential stuffing attacks against the affected user base. The sheer volume, while not astronomical, represents a substantial portion of their known user accounts.

The Nansei Feather breach, discovered on August 26, 2018, involved the compromise of their online portal. Approximately 9,821 records were exfiltrated, containing sensitive user information. The leaked data types are primarily email addresses and, critically, plaintext passwords. This combination is a potent threat vector, as it allows attackers to directly attempt credential reuse across other platforms. The breach appears to have originated from a direct database compromise, with the resulting data later being disseminated on a well-known hacking forum. The implications are significant, as this data could be leveraged for account takeovers, phishing campaigns, and further network intrusions.

While this specific breach did not garner widespread mainstream news coverage at the time of its initial discovery, its reappearance on underground forums is a common pattern for older, yet still valuable, datasets. Open-source intelligence (OSINT) indicates that such combolists, containing email and plaintext password pairs, are a staple for threat actors engaging in automated credential stuffing. Research from cybersecurity firms consistently highlights the persistent effectiveness of these attack methods against organizations that have not enforced robust password policies or implemented multi-factor authentication for their users.

We observed a significant data leak originating from a platform identified as "MyFitnessPal," with the initial compromise dating back to February 2018. The sheer scale of this incident, affecting over 150 million user accounts, immediately flagged it as a high-priority event for analysis. What is particularly concerning is the breadth of sensitive personal information exposed, extending beyond basic credentials to include dietary habits and health-related data, which introduces unique privacy and potential exploitation vectors for affected individuals. The continued availability and discussion of this dataset on dark web marketplaces underscore the enduring threat posed by large-scale breaches.

The MyFitnessPal breach, first disclosed in March 2018 following an incident in February, represents a substantial compromise of user data. The attackers gained access to a significant portion of the platform's user base, with an estimated 150 million records exposed. The leaked data types are extensive, including email addresses, hashed passwords (though some may be vulnerable to offline cracking), and user-generated content. This user-generated content is particularly noteworthy, as it includes detailed information about users' diets, exercise routines, and other personal health metrics. The breach is understood to have originated from unauthorized access to backend systems, with the data subsequently appearing on illicit marketplaces. The threat themes are multifaceted, ranging from account takeover and identity theft to highly targeted social engineering and the potential exploitation of sensitive health information for blackmail or discriminatory purposes.

This breach received considerable attention from major news outlets globally due to the platform's popularity and the sensitive nature of the data involved. Cybersecurity researchers have extensively analyzed the leaked data, highlighting the vulnerabilities in password hashing mechanisms and the privacy implications of exposing detailed health information. OSINT indicates that this dataset has been a recurring feature in credential stuffing lists and has been used in various phishing campaigns targeting users of health and fitness applications. The incident serves as a stark reminder of the importance of robust data security practices for platforms handling personal health information.

Our analysis uncovered a concerning data exposure event linked to "Verifications.io," a third-party data verification service. The discovery was made in April 2020, revealing an unsecured cloud storage bucket that had been accessible for an extended period. What immediately stood out was the sheer volume and sensitivity of the data contained within, representing a critical supply chain risk for numerous organizations that relied on Verifications.io for their own security and compliance processes. The implications of such a widespread exposure, impacting potentially millions of individuals through their association with multiple client companies, are profound and far-reaching.

The Verifications.io incident, identified in April 2020, involved the accidental exposure of a massive data repository. The unsecured cloud storage bucket contained an estimated 2 billion records, a staggering figure that underscores the scale of the compromise. The leaked data types are exceptionally broad, encompassing a wide array of personally identifiable information (PII) including names, email addresses, physical addresses, phone numbers, and employment details. This data was collected from numerous client companies that utilized Verifications.io for identity verification, background checks, and other data validation services. The breach was not a result of malicious intrusion but rather a misconfiguration of the cloud storage, leaving the data publicly accessible. The threat themes are primarily centered around identity theft, sophisticated phishing operations, and the potential for widespread fraud due to the comprehensive nature of the exposed PII.

This breach garnered significant media attention due to its immense scale and the fact that it impacted a service provider, thereby exposing data from many of its clients. News reports highlighted the potential for this data to be used for highly personalized scams and the challenges in notifying all affected individuals and organizations. Cybersecurity researchers have pointed to this incident as a prime example of the risks associated with third-party data handling and the critical need for robust access controls and continuous monitoring of cloud infrastructure. OSINT suggests that while the initial discovery was public, the data may have been further disseminated and utilized by threat actors in subsequent campaigns.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Plaintext Password
Password Types Plaintext
Date Leaked 14 Oct 2025
Check in 5 seconds

9,821 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,744 scanned today
Breach Rank #12,828 by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $71.1K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance