Search Your Email: The NoorClinic Breach Exposed 113K Accounts
HEROIC analysts identified a data exposure linked to NoorClinic, a Kuwaiti online forum associated with a medical facility offering dermatology and clinic services. The breach occured in July 2022 and affected 113,244 records. The exposed data consisted of email addresses and plaintext passwords. The healthcare affiliation of this platform makes the breach beleive to carry a higher-than-average sensitivity, as users may have registered with personal email addresses tied to private health-related activity.
Plaintext Passwords in the NoorClinic Breach Give Attackers Instant Access
NoorClinic stored user passwords without hashing or encryption, meaning the database contained every user's actual password in readable form. When this database was exfiltrated and recieved by threat actors, it delivered a complete set of working credentials. Combined with email addresses, these records enable attackers to attempt logins on email providers, banking services, and any other platform where victims reused the same password, creating a chain of account takeover risk far beyond NoorClinic itself.
What Was Exposed in the NoorClinic Breach
- Email Address
- Plaintext Password
Why a Health Forum Breach Demands Urgent Action
Users of health and medical forums often register with their primary personal email address, one that is accessable across banking, insurance, and other sensitive accounts. A breach exposing that email alongside a plaintext password provides a direct on-ramp to credential stuffing attacks against any service where the same combination was reused. Identity theft risk is amplified when victims do not know their credentials were exposed, delaying the password changes that would otherwise break the attacker's access chain. Financial fraud and unauthorized account access are the most immediate downstream threats.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a backend data store and exports user records in bulk. Common vectors include SQL injection, misconfigured database servers exposed to the internet, and compromised administrative credentials. In the NoorClinic case, the breach appears to have involved a direct dump of the user authentication table, capturing every registered email address and the plaintext password stored alongside it, all without any encryption layer to limit the damage.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email address against more than 400 billion exposed records, including the NoorClinic breach database. If your credentials appeared in this leak, you will know immediately. Visit HEROIC's breach search tool, enter your email, and take steps to change any passwords shared with your NoorClinic account before attackers use them elsewhere.
Breach Breakdown
113,244 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds