Profit Pips Leak: 11,366 Plaintext Passwords Hit a Forum
In August 2018, a dataset tied to Profit Pips, a now-defunct U.S.-based forex trading website, surfaced on a hacking forum. The dataset contains 11,366 records made up of email addresses and plaintext passwords. HEROIC has not independently verified this data came directly from Profit Pips's own systems, so it's presented as a dataset attributed to the site rather than a confirmed corporate breach.
Why the Profit Pips Leak Is Especially Dangerous
Plaintext passwords remove the single biggest obstacle an attacker normally faces: cracking a hash. Every one of the 11,366 passwords in this dataset is immediately usable, meaning anyone who downloads the file can start logging into accounts the moment they have it.
What Was Exposed in This Dataset
- Email addresses
- Plaintext passwords
Why This Matters Even for a Defunct Trading Site
Profit Pips shutting down doesn't erase the risk. Trading platforms often attract users who reuse the same password for financial accounts elsewhere, so a leaked Profit Pips password could be the key to a brokerage account, a bank login, or a cryptocurrency wallet.
How Plaintext Password Leaks Get Weaponized
Once a dataset like this is posted on a hacking forum, it's typically folded into larger combolists, giant collections of email and password pairs from many breaches combined. Attackers run these combolists through automated tools that test each pair against banking sites, exchanges, and email providers in bulk, a technique known as credential stuffing.
Check If You Are Affected
Search your email in HEROIC's free breach scanner, which checks against more than 400 billion breached records, to find out whether your data appears in this leak or any other exposure.
Breach Breakdown
11,366 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds