SAA Community Hack: 69K UK Art Community Accounts Exposed
DarkHive discovered a data breach affecting SAA Community, a UK-based online art community operated by the Society for All Artists. The breach exposed 68,977 records including email addresses and MD5 salted password hashes, with data leaked in August 2018. While salting adds a layer of protection compared to unsalted hashes, MD5 remains a cryptographically weak algorithm that modern GPU-powered cracking tools can still attack effectively, particularly for shorter or common passwords.
Why This Is Dangerous
Although salted MD5 hashes are harder to crack than unsalted ones, they are far from secure by modern standards. Attackers with GPU clusters can still work through common and moderately complex passwords in a matter of hours or days. Members of the SAA Community are typically artists, hobbyists, and art educators who may use the same password on art supply retailers, gallery registration sites, and personal email accounts. A compromised art community account could also expose creative portfolios, private messages, and personal contact information shared within the platform.
What Was Exposed
- Email Address
- Password Hash (MD5 with Salt)
- Salt
Why This Matters
The exposure of both the password hash and the salt in the same database dump means attackers can target individual accounts using the known salt value, making per-account cracking more efficient than attacking unsalted hashes in bulk. Users who reused thier SAA Community password on seperate platforms remain vulnerable even years after this breach. Online art communities attract dedicated users who often remain members for years, increasing the likelihood that original credentials were never changed. These 68,977 credential pairs entered combolist networks where they continue to fuel credential stuffing campaigns against active accounts on other platforms.
How Database Breach Works
A database breach occured when attackers gained unauthorized access to SAA Community's web infrastructure and extracted the user credential database. The inclusion of both hashes and salts in the extracted data means attackers could crack individual accounts using the known salt per record. This data entered combolist distribution networks on dark web forums and underground Telegram channels, where art and community platform credential sets are bundled with other consumer website breaches and traded for use in credential stuffing campaigns.
Check If You Are Affected
HEROIC offers a free identity scanner that checks your email address against known data breaches including the SAA Community breach. Visit heroic.com to run a free scan and find out if your credentials were exposed. If you were a member of SAA Community, change your password there and on any other platform where you used the same credentials. Enable two-factor authentication on all art and hobby community accounts to protect against account takeover even if credentials are compromised in future incidents.
Breach Breakdown
68,977 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds