Researchers Trace the Panapace Breach to 54,701 Stolen Thai User Accounts
HEROIC analysts identified the Panapace breach while scanning dark web forums, where the database had been circulating among threat actors targeting Thai internet users. The incident occured in August 2018 and exposed 54,701 records from this Thailand-based platform, including email addresses and MD5 hashed passwords. What struck our team was the renewed spike in mentions across Telegram channels known for trading compromised credentials, suggesting attackers were actively re-weaponizing this older dataset.
Why MD5 Password Hashes Put Panapace Users at Serious Risk
Attackers who obtain MD5 hashed passwords can run them through precomputed rainbow tables to recover the original plaintext credentials in hours. With email addresses also exposed, those cracked passwords become directly accessable for credential stuffing attacks against banking portals, email providers, and social media platforms where Panapace users may have registered with the same password. MD5 offers virtually no protection against modern cracking rigs.
What Was Exposed in the Panapace Breach
- Email Address
- Password Hash (MD5)
Why the Panapace Breach Still Threatens Users Today
Even though this breach dates to 2018, the threat has not expired. Attackers routinely recycle old breach data in credential stuffing campaigns, running recovered passwords against dozens of services simultaneously. Users who reused their Panapace password elsewhere face real account takeover, identity theft, and financial fraud risks. The weak MD5 algorithm makes the hashes partcularly easy to crack, which is why this dataset remains attractive years after the original exposure.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a backend database, typically by exploiting a software vulnerability, a misconfigured server, or stolen administrative credentials. Once inside, the attacker exports database tables containing user records. In the Panapace case, the exported records included user email addresses and their stored MD5 password hashes, which were then shared and sold on dark web forums where other threat actors could use them in downstream attacks.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion records to tell you instantly whether your email appeared in the Panapace breach or any other known data leak. Run a free scan at HEROIC to find out if your credentials are circulating on the dark web before attackers use them against you.
Breach Breakdown
54,701 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds