NeraSol Ghana Breach Exposed 242,394 Passwords and Phone Numbers
HEROIC analysts found a database breach affecting NeraSol Ghana Limited, a Ghanaian IT services company, dated August 1, 2024. The breach exposed 242,394 records containing email addresses, bcrypt password hashes, IP addresses, phone numbers, first names, and last names. The volume and variety of data types present in this leak make it one of the more comprehensive exposures seen from the West African technology sector.
Why This Is Dangerous
This breach combines identity data with authentication credentials and network identifiers in a single dataset. Attackers can cross-reference email addresses and bcrypt hashes with previously cracked password lists to identify accounts where users chose weak or reused passwords. IP addresses narrow down a user's approximate location and internet service provider, enabling targeted phishing tailored to local ISPs and services. Phone numbers add a SIM-swap attack surface on top of the credential risk, making multi-factor authentication bypasses more feasible for determined actors.
What Was Exposed
- Email Address
- Password Hash (bcrypt)
- IP Address
- Phone Number
- First Name
- Last Name
Why This Matters
A dataset of 242,394 records encompassing credentials, contact details, and network data is a ready-made toolkit for account takeover campaigns. Credential stuffing tools can test cracked or guessed passwords across email providers, banking apps, and social platforms within hours of a breach publication. Identity thieves can open fraudulent accounts using full names combined with email addresses. The inclusion of IP addresses also helps attackers craft geographically convincing phishing messages that appear to come from a known local network or service provider, increasing click-through rates on malicious links.
How Database Breaches Work
A database breach occurs when an unauthorized party gains direct read access to a company's backend data store. Common entry points include SQL injection against web-facing applications, exploitation of unpatched database software, exposed administrative interfaces with default or weak credentials, and compromised staff accounts. NeraSol's role as an IT services provider means its databases may aggregate data from multiple client operations, potentially widening the blast radius beyond its own direct user base. Once an attacker exports a database table, the data is typically compressed and sold or published on breach forums within days.
Check If You Are Affected
If you held an account with NeraSol Ghana Limited or any service they managed, your credentials and contact details may already be circulating online. HEROIC's free scanner checks against more than 400 billion exposed records. Run a free scan now to see whether your email or phone number appears in this or any other known breach.
Breach Breakdown
242,394 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds