PCDriverDownloads
We noticed a recent resurgence of data originating from a breach that occurred in August 2018, impacting the United States-based device driver repository, PCDriverDownloads. The initial compromise, which exposed approximately 15,000 records, has resurfaced on a prominent cybercrime forum. What struck us was the continued utility of these older credentials, particularly the MD5 hashed passwords, in current credential stuffing campaigns. This underscores the persistent threat posed by even outdated hashing algorithms when paired with commonly reused passwords.
The PCDriverDownloads breach, discovered on August 26, 2018, involved a database compromise. Approximately 11,016 unique email addresses and their associated MD5 hashed passwords were exfiltrated. This data has since been observed being distributed as a combolist, a common tactic to facilitate automated credential stuffing attacks. The significance lies in the fact that these credentials, despite their age and the weak hashing algorithm, are likely still active for a portion of the affected user base. The threat theme here is the enduring risk of legacy data breaches and the effectiveness of simple, brute-force attack vectors against poorly secured credentials.
While this specific breach did not garner widespread mainstream news coverage at the time of its initial discovery, it aligns with a broader trend of older, less secure databases being exploited. Research from various cybersecurity firms consistently highlights the prevalence of MD5 hashed passwords in leaked datasets, and their continued use in credential stuffing operations. The availability of such lists on cybercrime forums directly fuels these attacks, making it imperative for organizations to monitor for their own data, regardless of the breach's vintage.
Breach Breakdown
11,016 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds