Re Bu Musikagentur
We've been tracking a noticeable uptick in older breaches resurfacing in combolists and credential stuffing attacks. It's not just the volume, but the age of some of these leaks – some dating back nearly a decade – that's concerning. The persistence of plaintext passwords in these older datasets makes them particularly dangerous. What caught our attention was the cleartext exposure of passwords tied to a relatively niche target: a German music agency.
Re Bu Musikagentur Breach: Plaintext Passwords Resurface After Six Years
In August 2018, Re Bu Musikagentur, a German music agency specializing in artist booking and entertainment, suffered a data breach. This breach, impacting 9,744 users, has now resurfaced on hacking forums, with the compromised data including both email addresses and, critically, plaintext passwords. The leak was first documented on August 21, 2018, but its re-emergence highlights the long tail of risk associated with poorly secured data.
The fact that passwords were stored in plaintext, even in 2018, is a significant security lapse. While not the largest breach we've seen, the exposure of plaintext credentials provides attackers with a direct pathway to account takeover, not only on the Re Bu Musikagentur platform, but also potentially on other services where users may have reused those same passwords. This highlights the continued relevance of basic security hygiene, even years after an initial breach. This breach matters to enterprises now because it's a case study in the enduring risk of poor security practices. Even smaller breaches can have disproportionate impact when basic security principles are ignored.
- Total records exposed: 9,744
- Types of data included: Email Addresses, Plaintext Passwords
- Source structure: Database, Combolist
- Date leaked: August 21, 2018
While there hasn't been widespread reporting on this specific breach in mainstream media outlets, the incident underscores the broader trend of older data breaches being weaponized in modern attacks. Threat actors frequently compile these older datasets into massive combolists used for credential stuffing attacks across various online platforms. The "spray and pray" approach often finds success due to password reuse and the surprisingly large number of individuals still using easily guessable passwords. Similar cases involving plaintext password storage have been widely reported; for example, the 2019 VinWiki breach, which also exposed plaintext passwords, led to widespread account compromise across various services (source: KrebsOnSecurity).
Breach Breakdown
9,744 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds