18,429 Portal Metalica Records Leaked With Plaintext Passwords
HEROIC analysts identified a dataset tied to Portal Metalica, a Brazilian web hosting and IT services company, posted on a prominent hacking forum in August 2018. The breach exposed 18,429 user records, each containing an email address paired with a plaintext password. This data resurfaced on dark web forums years later, confirming that old breaches rarely stay buried and continue to put real people at risk long after the orignal incident.
Why This Is Dangerous
An attacker holding 18,429 email and plaintext password pairs can immediately begin testing those credentials across Gmail, banking apps, social media, and corporate logins. Because passwords were stored in plain text, there is no cracking step required. Anyone on that list who reused their Portal Metalica password anywhere else is at serious risk of account takeover right now.
What Was Exposed
- Email addresses
- Plaintext passwords
Why This Matters
Storing passwords in plaintext is one of the most dangrous mistakes a website can make. When attackers get this data, they do not need to guess or crack anything. They simply try your email and password on other sites. This technique, called credential stuffing, is responsible for milions of account takeovers every year. If your Portal Metalica credentials match anything you use today, those accounts are exposed. Identity theft and financial fraud are common outcomes when attackers chain these breaches together.
How Database Breaches Work
A database breach happens when attackers gain unauthorized access to a website's back-end storage, usually through a security vulnerability, stolen administrator credentials, or an unpatched software flaw. Once inside, they export the user table, which holds every registered account. The exported file is then shared or sold on hacking forums, where other criminals can download it and begin using the credentials. In Portal Metalica's case, the exported user table went directly onto a public forum, making the data instantly accessible to anyone looking for it.
Check If You Are Affected
HEROIC's free breach scanner searches across more than 400 billion exposed records to tell you whether your email address appears in the Portal Metalica breach or any other known leak. Run a free check right now and find out if your credentials are already in the hands of attackers.
Breach Breakdown
18,429 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds