If You Reuse Passwords, the Relink.to Breach Should Worry You
HEROIC analysts flagged the Relink.to breach after the database surfaced in credential aggregation feeds monitored by our research team. The breach occured in October 2018 and affected 116,073 users of this now-defunct Austria-based cryptocurrency platform. Exposed records contained email addresses and plaintext passwords, meaning the credentials required no cracking and were immediately usable by any attacker who obtained the data.
Plaintext Passwords: The Worst-Case Scenario for Relink.to Users
When a site stores passwords in plaintext, there is no protective layer between the raw database and an attacker. Anyone with accessable access to the dump has working credentials. With 116,073 email and password pairs exposed in cleartext, attackers can run automated login scripts against Gmail, PayPal, banking apps, and cryptocurrency exchanges to find accounts where the same password was reused. Cryptocurrency users are partcularly high-value targets given the irreversibility of crypto transactions.
What Was Exposed in the Relink.to Breach
- Email Address
- Plaintext Password
Why Reusing Passwords After a Breach Like Relink.to Is Dangerous
Credential stuffing tools can test thousands of login combinations per minute across dozens of platforms simultaneously. If you used the same email and password on Relink.to as you did on your bank, your crypto wallet, or your work email, that account is now accessible to anyone who purchased this breach data. Identity theft, financial fraud, and account takeover all beleive on credential reuse as their primary fuel, and plaintext leaks like this one are the most potent source material available to attackers.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a site's backend data store, often through SQL injection, unpatched software vulnerabilities, or compromised server credentials. The attacker then exports user records and distributes the data on dark web forums, Telegram channels, or breach aggregation sites. Databases containing plaintext passwords are especially prized because they require no additional processing before being weaponized in automated attacks.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion compromised records, including data from the Relink.to breach, to tell you instantly whether your email address has been leaked. Search your email now at HEROIC to find your full exposure report and get guidance on which accounts need immediate password changes.
Breach Breakdown
116,073 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds