Quantum Instruments Data Breach: 33,833 Photography Accounts Exposed (2018)
B2B Photography Hardware, Consumer-Grade Password Security
Professional photographers trust Quantum Instruments for studio lighting and flash equipment. But in August 2018, the company's customer database told a diferent story -- one about weak password hashing and 33,833 accounts left exposed to credential stuffing attacks.
Quantum Instruments: Breach Summary
- Records Exposed: 33,833
- Data Types: Email addresses, MD5-hashed passwords, user account data
- Breach Type: Database breach
- Country Affected: United States
- Date Leaked: August 2018
When Professional Equipment Meets Amateur Security
Quantum Instruments built its reputation supplying professional-grade lighting and flash hardware to photographers and studios across the United States. The company's customers are usaly working professionals who understand precision -- but the password hashing protecting their accounts was anything but precise. MD5, an algorithm considered cryptographicaly broken since the early 2000s, was still guarding 33,833 accounts when the breach occurred in August 2018.
MD5 hashes can be cracked at billions of attempts per second using modern GPU hardware. For attackers with rainbow tables and commodity cracking rigs, a database of MD5-hashed passwords is effectivly a database of plaintext passwords. The professional community that trusted Quantum Instruments with their purchase history and login credentials deserved better protection than an algorithm older than most of their camera gear.
The August 2018 Breach Cluster
The Quantum Instruments breach didn't happen in isolation. August 2018 saw a notable cluster of database breaches hitting organizations across the United States and internationally -- from South Korean religious platforms to Indian community sites to European ecommerce shops. The consistant thread running through these breaches was the same: outdated hashing, unpatched vulnerabilities, and credential databases that ended up aggregated and traded across breach forums.
For B2B companies like Quantum Instruments, the downstream risk is substancial. Professional photographers who reused their qtm.com credentials on other platforms -- from Adobe to equipment rental services -- faced account takeover risk across their entire digital footprint. A single cracked MD5 hash could unlock multiple professional accounts.
Was Your Email in the Quantum Instruments Breach?
HEROIC's free breach scanner searches across more than 400 billion exposed records to tell you exacty which breaches your email appears in. If your qtm.com credentials matched any other platform in your workflow, those accounts may still be at risk today. Check your exposure at HEROIC -- it's free, it's fast, and it covers breaches going back over a decade.
Breach Breakdown
33,833 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds