Rapid Intelligence Data Breach: 28,652 Australian Analytics Platform Accounts (2018)
When the Intelligence Platform Has No Intelligence About Its Own Security
Rapid Intelligence was an analytics and domain research platform -- the kind of tool used by SEO professionals, digital marketers, and domain investors who needed data on web properties, traffic patterns, and competitive intelligence. In February 2018, 28,652 user accounts from this Australian-hosted platform were exposed, with email addresses and MD5-hashed passwords leaking from a site whose entire value propostion was built on gathering and analyzing information -- about everything except, apparently, its own security posture.
Rapid Intelligence (February 2018): Breach Summary
- Records Exposed: 28,652
- Data Types: Email addresses, MD5 password hashes
- Breach Type: Database breach
- Country Affected: Australia
- Date Leaked: February 7, 2018
Analytics Professional Credentials: A Business Tool Reuse Target
Users of domain research and analytics platforms tend to maintain accounts across a broad ecosystem of professional tools: Google Search Console, Google Analytics, SEMrush, Ahrefs, Moz, domain registrars, web hosting platforms, and client reporting tools. Many of these tools are linked to business accounts with billing information and elevated organizational access. When credentials from Rapid Intelligence are cracked (MD5 hashes crack quickly against rainbow tables), attackers gain a tested email/password pair to try across every marketing and business tool the victim might use. The analytics professonal's credential set is high-value precisely because of the breadth of the platforms it unlocks.
MD5 on an Analytics Platform: The Security Irony
Rapid Intelligence's users were, by professional nature, people who analyzed data and drew conclusions from it. The platform itself stored their passwords using MD5 -- an algorithm that the infosec comunity had analyzed extensively and concluded was inadequate for password storage well before 2018. The irony is notable: a tool built to provide intelligence failed to apply basic intelligence to its own credential storage. For the 28,652 affected users, the consequence was an exposure that could have been significntly mitigated by simply using bcrypt or another modern hashing algorithm instead.
February 2018: The Earliest Breach in This Dataset
The Rapid Intelligence breach leaked on February 7, 2018 -- the earliest 2018 breach in the current dataset, predating the March breaches (DLC Quickplay, Reeqwest) and the large August cluster by six months. Users exposed in February 2018 faced an extended period of undetected exposure before later breach releases began to raise awareness of the aggregation activity that had been quietly building throughout the year. The data's early entry into breach markets meant it had more time to circulate and be incorporated into credential stuffing tools before users had any reason to suspect they were affected.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records -- including analytics platforms, domain research tools, and Australian business services. If you've ever registered on Rapid Intelligence or similar platforms, check now to see if your credentials are in breach databases.
Breach Breakdown
28,652 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds