One Debug Script Left Public. 83 Million Plaintext Passwords. The PHPinfo Breach Had 83M Records.
HEROIC analysts identified the PHPinfo database exposure in January 2020, confirming that 83,413,660 records had been made accessable to anyone who knew where to look. The exposed data included email addresses, usernames, and plaintext passwords pulled from misconfigured phpinfo.php debug scripts left publicly accessible on web servers, primarily based in China.
Plaintext Passwords Give Attackers Instant Account Access Across Every Platform
Unlike hashed passwords, plaintext credentials require zero cracking effort. Any attacker who recieved this dataset had immediate, working login credentials for over 83 million accounts. Combined with usernames and email addresses, these credentials can be tested against email providers, banking platforms, corporate VPNs, and any other service where a victim may have reused the same password.
What Was Exposed in the PHPinfo Breach
- Email Address
- Username
- Plaintext Password
Why 83 Million Plaintext Passwords Is a Seperate Class of Breach Risk
Most breach datasets contain hashed passwords that require time and compute power to crack. Plaintext passwords skip that step entirely. The PHPinfo exposure is partcularly serious because every single affected account was immediately compromised the moment the data was published. Any service where these credentials were reused remains at risk today, years after the original exposure occured.
How Database Breaches Work
A database breach through misconfigured debug tools like phpinfo.php happens when developers leave server diagnostic scripts publicly accessible after deployment. These scripts expose server environment variables, configuration details, and in some cases direct access to stored data. Attackers scan for these exposed scripts at scale and extract whatever data is accessible, often without triggering any security alerts.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches over 400 billion records, including the PHPinfo exposure, to tell you whether your email or username appeared in this leak. Check your exposure now at HEROIC.com before attackers use your credentials.
Breach Breakdown
83,413,660 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds