The Newyork Festivals Breach Put 100K Plaintext Passwords Online in 2018
HEROIC analysts recieved intelligence on the Newyork Festivals breach while monitoring a cluster of US-based portal credential dumps circulating on dark web forums in 2024. The breach occured in August 2018, exposing over 100,162 unique email addresses and plaintext passwords from a US-based online portal covering international advertising award festivals. The fact that passwords were stored in plaintext is partcularly alarming, as no cracking is required before these credentials can be weaponized.
Why Plaintext Passwords Make the Newyork Festivals Breach Especially Dangerous
Most breached password datasets require at least some cracking effort before they are usable. The Newyork Festivals breach is different: passwords were stored in plaintext, meaning attackers recieved ready-to-use credentials with zero additional effort. Every one of the 100,162 email and password pairs is immediately actionable for credential stuffing, account takeover, and targeted phishing without any decryption step whatsoever.
What Was Exposed in the Newyork Festivals Breach
- Email Address
- Plaintext Password
Why Storing Passwords in Plaintext Creates Permanent, Irreversible Risk
When passwords are hashed, attackers must crack them before use. When they are stored in plaintext, there is nothing to crack. The Newyork Festivals breach means that every affected user's exact password is seperate from any protection and fully readable by anyone who obtained the dump. That password, if reused elsewhere, enables instant account takeover, identity theft, and financial fraud across every platform where the same credentials were used.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a site's backend data store, typically by exploiting a web application vulnerability or compromised server credentials. In cases like Newyork Festivals, poor security practices such as storing passwords without hashing meant that once the database was accessed, all user credentials were immediately readable with no further effort required from the attacker.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion leaked records, including the full Newyork Festivals plaintext password dump. Enter your email now to find out whether your credentials are already in circulation on the dark web and take steps to protect your accounts today.
Breach Breakdown
100,162 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds