The OSSRC Database Could Unlock Email and Bank Accounts
We noticed a recent analysis of historical data dumps revealing a previously under-reported incident impacting the Ohio South State Referee Committee (OSSRC). This breach, surfacing in February 2018, exposed a significant number of user credentials. What struck us was the inclusion of plaintext passwords alongside email addresses, a particularly egregious oversight in terms of data security hygiene. The scale, while not astronomical, is substantial for a niche organization, suggesting a broader impact than initially apparent on the affected individuals and potentially the wider soccer community in the region.
The incident originated from a database compromise, with the resulting data appearing on a prominent hacking forum. A total of 15,228 records were exfiltrated, comprising user email addresses and, critically, their corresponding passwords in a clear, unencrypted format. This type of exposure significantly elevates the risk of credential stuffing attacks and unauthorized account access. The data structure suggests a direct dump from a user authentication database, likely facilitated by a SQL injection vulnerability or compromised administrative credentials. The leak location on a well-known forum indicates a deliberate attempt to disseminate the compromised information to a wider audience of malicious actors.
While this specific breach did not generate widespread mainstream news coverage at the time, its implications align with broader trends in credential compromise. The OSSRC breach is a textbook example of the risks associated with storing sensitive authentication data insecurely. Similar incidents, such as the numerous breaches affecting online services and forums that have led to the creation of large-scale combolists, underscore the persistent threat of credential reuse. The exposure of plaintext passwords, in particular, remains a critical vulnerability that attackers actively exploit, often gaining access to other, more sensitive systems if users have employed the same credentials across multiple platforms.
Breach Breakdown
15,228 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds