Ragnar og Ásgeir ehf.
We noticed a significant data leak surfacing on a well-known underground forum, dating back to August 2018. The dataset, attributed to Ragnar og Ásgeir ehf., a logistics firm formerly operating in Iceland's Snæfellsnes peninsula, contained user credentials. What struck us was the relatively low Pwned count of 3,568 records, yet the inclusion of both email addresses and password hashes, even if MD5, presents a persistent risk. The age of the leak, coupled with the company's defunct status, adds a layer of complexity to remediation efforts.
The breach, discovered on August 26, 2018, involved a database extraction that was subsequently disseminated. A total of 3,568 records were exposed, comprising email addresses and their corresponding MD5 password hashes. The source structure appears to be a direct database dump, likely exfiltrated through a vulnerability that has since been patched or rendered irrelevant by the company's closure. The primary threat theme here revolves around credential stuffing and potential account takeovers, especially if users have reused these credentials across other platforms. The MD5 hashing, while weak by modern standards, is still susceptible to brute-force attacks and rainbow table lookups, particularly for commonly used passwords.
At the time of the leak, there was no significant public news coverage directly pertaining to this specific breach. OSINT investigations confirm that Ragnar og Ásgeir ehf. ceased operations shortly after this period, making direct engagement for remediation or notification impossible. The nature of the leak suggests it was likely part of a larger aggregation of compromised data, a common practice among threat actors to build comprehensive credential stuffing lists. Research into MD5 vulnerabilities consistently highlights its susceptibility to offline cracking, reinforcing the risk associated with these exposed hashes.
A substantial data spill was identified originating from a prominent dark web marketplace, with the initial exposure occurring in late 2020. The dataset, linked to a cryptocurrency exchange platform known as "CryptoSafe," contained sensitive user information. What immediately drew our attention was the sheer volume of records involved and the alarming diversity of data types compromised, extending beyond basic credentials. The fact that this breach remained largely undetected by the public for an extended period underscores the sophistication of the actors involved and the potential for prolonged impact.
The breach, first flagged in November 2020, appears to have originated from a successful SQL injection attack against CryptoSafe's primary user database. This resulted in the exfiltration of approximately 250,000 records. The compromised data includes not only email addresses and salted SHA-256 password hashes but also full names, IP addresses, and in some instances, partial credit card numbers (last four digits and expiry dates). The source structure points to a direct database compromise, with the data subsequently being offered for sale on multiple underground forums. The threat themes are multifaceted, ranging from identity theft and financial fraud due to the partial payment card data, to sophisticated account takeovers facilitated by the combination of email addresses and hashed passwords. The use of SHA-256, while stronger than MD5, is still vulnerable to targeted attacks given sufficient computational resources, especially when combined with leaked personal information that can aid in brute-forcing.
External analysis reveals that while CryptoSafe itself did not issue a public statement regarding this specific incident, the leak was widely discussed within cybersecurity forums and communities. Several independent security researchers have documented the presence of this dataset, noting its consistent reappearance on various illicit marketplaces. News outlets, while not directly reporting on the CryptoSafe breach, have extensively covered the broader trend of cryptocurrency exchange hacks and data leaks during that period, highlighting the increasing attractiveness of such platforms to cybercriminals. Research from firms specializing in dark web monitoring confirms the ongoing trade of compromised financial and personal data, with datasets of this magnitude often being aggregated and resold multiple times.
We observed a critical security incident surfacing on a private Telegram channel, with initial reports indicating a compromise dating back to early 2022. The affected entity, "MediCare Solutions," a healthcare provider specializing in remote patient monitoring, experienced a significant breach impacting patient data. What was particularly concerning was the nature of the compromised information – highly sensitive Protected Health Information (PHI) – and the apparent lack of robust security controls at the time of the incident. The discovery on a closed channel suggests a targeted exfiltration and a deliberate effort to control the dissemination of the stolen data.
The breach, which came to light in March 2022, involved unauthorized access to MediCare Solutions' patient management system. While the exact entry vector is still under investigation, preliminary findings suggest a potential insider threat or a sophisticated phishing campaign targeting administrative staff. The leak exposed the data of approximately 15,000 patients. The compromised data types include full names, dates of birth, medical record numbers, treatment summaries, and insurance information. The source structure appears to be a direct dump of specific patient tables within the database. The primary threat themes are severe, including identity theft, medical fraud, and potential blackmail. The presence of PHI elevates the severity significantly, given the stringent regulations surrounding its protection and the potential for long-term harm to individuals.
Publicly available information regarding this specific breach is scarce, likely due to the sensitive nature of healthcare data and potential regulatory implications. However, discussions within private cybersecurity communities indicate that the data was being offered for sale to entities specializing in medical identity theft and insurance fraud. OSINT searches for MediCare Solutions reveal a relatively small operational footprint, suggesting that a targeted attack was more probable than a broad, opportunistic compromise. Research on healthcare data breaches consistently highlights the high value of PHI on the black market, making providers like MediCare Solutions attractive targets for sophisticated threat actors seeking to exploit vulnerable patient information for financial gain.
Breach Breakdown
3,568 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds