The Riben Breach Happened in 2018. The Plaintext Passwords Are Still Circulating.
HEROIC analysts identified the Riben breach while reviewing a dark web forum where stolen credential databases are regularly posted and traded. The breach occured in April 2018 at Riben, a Japanese general business platform, and exposed 29,234 user records including email addresses and plaintext passwords. Because passwords were stored without any hashing or encryption, every single credential in this database was immediately usable by anyone who got their hands on the data. That data has now been circulating for years, giving attackers ample time to exploit it across other platforms.
Why Plaintext Passwords in the Riben Breach Put Users at Immediate Risk
When a site stores passwords in plaintext, a breach becomes instantly actionable for attackers. There is no cracking step, no time spent reversing a hash. With the Riben breach, anyone who obtained the database had a ready-made list of working email and password pairs. Attackers then test those pairs against popular services using automated tools in what is known as credential stuffing, targeting banking apps, email accounts, and shopping sites where users are partcularly likely to have reused the same password.
What Was Exposed in the Riben Breach
- Email Address
- Plaintext Password
Why the Riben Breach Timing Makes It Even More Concerning
The Riben breach occured in April 2018, but the data went public in August of that same year and has continued to circulate ever since. Years of exposure means these credentials have had time to be sold, resold, and incorporated into massive combined dumps used in large scale automated attacks. Users who have not changed their passwords since 2018 remain at genuine risk of account takeover, identity theft, and in some cases financial fraud if that password was reused on a banking or payment platform.
How Database Breaches Work
A database breach happens when an attacker gains unauthorized access to a company's internal data storage, often through a software flaw or a poorly secured server. The attacker copies the user database and takes it offline. That data is then shared privately or sold to other criminals before eventually appearing on public forums and breach aggregation sites. The longer it goes undetected, the more hands that data passes through.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion leaked records, including data from the Riben breach. If your email address appears in this database, your original password was stored in plain text and may have already been used in attacks against your other accounts. Run your free scan at HEROIC.com to find out right now.
Breach Breakdown
29,234 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds