PGSS Kroton
We noticed the reappearance of a dataset associated with PGSS Kroton, a Brazilian educational platform now operating under the name PGSS Cogna. This particular leak, originally dated August 26, 2018, has resurfaced, indicating potential re-use of compromised credentials or renewed interest from threat actors. What struck us was the combination of relatively common data types – email addresses and password hashes – with the inclusion of both MD5 and bcrypt hashing algorithms, suggesting a mixed security posture within the compromised system at the time.
The breach, affecting 4,709 unique records, involved the exfiltration of email addresses and their corresponding password hashes. Analysis of the leaked data reveals a dual approach to password security, with some credentials protected by the less secure MD5 algorithm and others by the more robust bcrypt. This inconsistency is a significant factor, as MD5 hashes are considerably easier to crack through brute-force or rainbow table attacks, potentially yielding plaintext passwords for a subset of affected users. The data was initially distributed on a prominent hacking forum, a common vector for credential stuffing and further malicious exploitation. The nature of this breach, stemming from a database compromise and subsequently contributing to credential stuffing lists, highlights the persistent threat of credential reuse and the impact of even older, less secure hashing methods.
While this specific incident from 2018 did not generate widespread media attention at the time of its initial discovery, the resurfacing of such datasets is a recurring theme in cybersecurity. Educational platforms, particularly those handling large volumes of student and staff data, remain attractive targets for attackers seeking personally identifiable information and credentials for further network intrusion. Research from organizations like Troy Hunt's "Have I Been Pwned" consistently demonstrates the prevalence of older breaches and the ongoing impact of credential stuffing attacks fueled by these exposed databases.
Breach Breakdown
4,709 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds