Breach Intelligence Report 13 Jun 2025

The Riben Breach Happened in 2018. The Plaintext Passwords Are Still Circulating.

HEROIC
HEROIC Threat Intelligence Team
Email Address Plaintext Password
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 29,234
Source Type Database
Origin Darkweb
Password Type Plaintext

HEROIC analysts identified the Riben breach while reviewing a dark web forum where stolen credential databases are regularly posted and traded. The breach occured in April 2018 at Riben, a Japanese general business platform, and exposed 29,234 user records including email addresses and plaintext passwords. Because passwords were stored without any hashing or encryption, every single credential in this database was immediately usable by anyone who got their hands on the data. That data has now been circulating for years, giving attackers ample time to exploit it across other platforms.


Why Plaintext Passwords in the Riben Breach Put Users at Immediate Risk

When a site stores passwords in plaintext, a breach becomes instantly actionable for attackers. There is no cracking step, no time spent reversing a hash. With the Riben breach, anyone who obtained the database had a ready-made list of working email and password pairs. Attackers then test those pairs against popular services using automated tools in what is known as credential stuffing, targeting banking apps, email accounts, and shopping sites where users are partcularly likely to have reused the same password.


What Was Exposed in the Riben Breach

  • Email Address
  • Plaintext Password

Why the Riben Breach Timing Makes It Even More Concerning

The Riben breach occured in April 2018, but the data went public in August of that same year and has continued to circulate ever since. Years of exposure means these credentials have had time to be sold, resold, and incorporated into massive combined dumps used in large scale automated attacks. Users who have not changed their passwords since 2018 remain at genuine risk of account takeover, identity theft, and in some cases financial fraud if that password was reused on a banking or payment platform.


How Database Breaches Work

A database breach happens when an attacker gains unauthorized access to a company's internal data storage, often through a software flaw or a poorly secured server. The attacker copies the user database and takes it offline. That data is then shared privately or sold to other criminals before eventually appearing on public forums and breach aggregation sites. The longer it goes undetected, the more hands that data passes through.


Check If Your Data Was Exposed

HEROIC's free breach scanner searches more than 400 billion leaked records, including data from the Riben breach. If your email address appears in this database, your original password was stored in plain text and may have already been used in attacks against your other accounts. Run your free scan at HEROIC.com to find out right now.

Breach Breakdown

Domain N/A
Leaked Data Email Address, Plaintext Password
Password Types Plaintext
Date Leaked 13 Jun 2025
Check in 5 seconds

29,234 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,257 scanned today
Breach Rank #7,470 by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $211.5K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance